v2-ether-fi[.]org
Зведення доказів
Analysis of the domain v2-ether-fi.org shows that it was registered on February 21, 2026 and is presently taken offline. The site was served over HTTPS using a certificate identified as WE1, and its DNS resolves to the IP address 104.21.80.1, which belongs to the Cloudflare network (AS13335, United States). VirusTotal scans recorded 13 positive detections out of 95 security vendors, indicating that multiple antivirus and threat‑intelligence engines have flagged the domain as malicious. AlienVault Open Threat Exchange lists the domain in 14 separate threat‑intel pulses, confirming that it has been observed across multiple independent feeds.
The domain is currently blocked by the PhishDestroy platform and appears on a single external security blocklist, reinforcing its classification as a malicious resource. The threat type is catalogued as a generic phishing campaign with a specific focus on a crypto‑related scam, and the risk level is elevated. Concrete evidence therefore includes registration date, SSL certificate label, hosting IP and ASN, detection counts from VirusTotal, OTX pulse count, and blocklist presence.
Uncertained aspects comprise the exact page content, any Safe Browsing verdicts, the registrar name, and the underlying phishing kit, as these details were not disclosed in the available intelligence. Defenders should incorporate the IP address 104.21.80.1 and the domain v2-ether-fi.org into URL filtering and DNS sink‑hole rules, verify that endpoint protection solutions update to include the 13 vendor detections, and monitor threat‑intel feeds for any re‑activation of the domain. Continuous observation of Cloudflare‑hosted assets associated with this IP is advised, as threat actors frequently repurpose such infrastructure for new campaigns.
Data Coverage
Процес реагування на загрози Pipeline
Перевірка за блок-листами
10 зовнішніх джерел під наглядом · знімок від 11.08.2026
Криміналістичні дані
Аналіз VirusTotal
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога