heavenmarketing[.]pk
“Default Web Site Page”
heavenmarketing.pk — Контент недоступний. Тип шахрайства: Brand Impersonation. Зведення доказів: VirusTotal 5/91 (alphaMountain.ai, CRDF, Gridinsoft, SOCRadar, Webroot); URLQuery 3 alerts; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 75/100.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
This domain, heavenmarketing.pk, is confirmed as a brand impersonation site targeting Aave, a decentralized finance protocol. Analysis indicates the site was designed to mimic legitimate Aave interfaces, likely to facilitate unauthorized cryptocurrency transactions or credential harvesting. No specific drainer kit signatures were identified in available telemetry, but the domain structure and content align with known impersonation tactics used in crypto-related fraud schemes. Technical indicators reveal the domain was flagged by 5 out of 95 security vendors on VirusTotal, with a Gridinsoft trust score of 0/100 and a Scamadviser score of 1/100. The domain was registered on April 28, 2026, and resolved to the IP address 162.0.232.43. It appears on three security blocklists and was included in one AlienVault OTX threat intelligence pulse. The registrar details are not publicly disclosed, but the domain's creation date suggests it was deployed with malicious intent shortly after registration. Google Safe Browsing status is not explicitly noted, but the domain's presence on multiple blocklists confirms its classification as malicious. As of the latest assessment, heavenmarketing.pk has been taken offline, reducing immediate exposure risk. However, the infrastructure associated with the IP address (162.0.232.43) may still pose residual threats, as it could be reused for future malicious campaigns. Organizations and users are advised to block the domain and its associated IP at the network level. Monitoring for similar impersonation domains targeting Aave or other decentralized finance platforms is recommended, particularly those registered under suspicious TLDs or with recent creation dates. Users who interacted with the domain should revoke any connected wallet permissions and audit transaction histories for unauthorized activity.
Розвіддані з мережевої безпеки
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| OpenDNS | heavenmarketing.pk |
phishing | Phishing Block |
| Hagezi Threat Feed | heavenmarketing.pk |
malicious | Sinkholed |
| DNS4EU | heavenmarketing.pk |
malicious | Sinkholed |
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Аналіз VirusTotal
Аналіз продуктивності сайту
Google PageSpeed Insights — mobile performance audit of heavenmarketing.pk · checked Jun 26, 2026
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога