portal-aave[.]co
portal-aave.co — Неперевірений. Уособлення бренду: Aave; Тип шахрайства: Brand Impersonation. Зведення доказів: VirusTotal 3/91 (CRDF, Gridinsoft, SOCRadar); 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 66/100. Реєстратор: DYNADOT.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
PhishDestroy identifies portal-aave.co as an active brand impersonation domain targeting Aave users. This fraudulent site mimics the legitimate Aave protocol to deceive victims into entering sensitive credentials or cryptocurrency wallet information. The threat type is specifically 'brand impersonation,' leveraging the trust associated with the Aave brand to execute credential harvesting or cryptocurrency draining schemes. No advanced drainer kit artifacts, such as obfuscated JavaScript or known malware payloads, have been observed during initial analysis, suggesting a basic but effective phishing landing page designed to harvest user inputs.
This domain was flagged with a VirusTotal detection score of 0/95, indicating it is not yet widely recognized as malicious by antivirus engines. It resolves to IP address 188.114.96.3, registered through Dynadot Inc on April 26, 2026. The domain utilizes a Let's Encrypt SSL certificate, which does not inherently indicate legitimacy, as threat actors frequently exploit free certificate authorities to appear more authentic. As of this report, the domain remains unblocked by Google Safe Browsing (GSB) and has not been listed on major threat intelligence blocklists, allowing it continued availability on the open web.
The current status of this domain is 'active,' and it remains under investigation by threat intelligence teams. While the immediate risk is assessed as 'under_investigation,' the lack of detections and blocklisting suggests a window of opportunity for malicious operations. Users are strongly advised to avoid interacting with portal-aave.co or any similar Aave impersonation domains. Security teams should monitor this domain for escalation in malicious activity and consider proactive blocking based on domain and IP indicators. Remaining risk includes potential credential theft, financial loss, or further compromise of cryptocurrency assets through social engineering and impersonation tactics.
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Аналіз VirusTotal
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога