7r6xed4a5dhivfhhxg6j2sjzo55l2bt2ckrjcctsxndurub3rdqq[.]arweave[.]net
“Loading…”
7r6xed4a5dhivfhhxg6j2sjzo55l2bt2ckrjcctsxndurub3rdqq.arweave.net — 内容不可用. 诈骗类型:Brand Impersonation. 证据摘要: VirusTotal 3/91 (Forcepoint ThreatSeeker, LevelBlue, Phishing Database); URLQuery 1 alert; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 66/100. 注册商: Namecheap.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
This domain is flagged as an elevated-risk brand impersonation threat targeting Aave, a decentralized finance protocol. The site was designed to mimic legitimate Aave interfaces, likely to harvest user credentials, private keys, or seed phrases. Analysis of the page title (Loading…) and infrastructure suggests a hastily deployed spoof intended to exploit users seeking Aave’s official platform for transactions or account access. The domain’s deceptive design and technical indicators align with common tactics used in cryptocurrency phishing campaigns, where victims are tricked into entering sensitive information on fraudulent sites. Infrastructure analysis reveals the domain was registered through NAMECHEAP INC and resolves to the IP address 79.127.211.89. It uses a Let’s Encrypt SSL certificate, which is frequently leveraged by threat actors to create a false sense of security. The domain appears on two security blocklists and is blocked by MetaMask and SEAL, two tools commonly used to detect and prevent fraudulent activity in the cryptocurrency space. VirusTotal reports that 3 out of 95 security vendors flag this domain as malicious, further corroborating its association with phishing activity. The use of CDN77 for content delivery indicates an attempt to obscure the origin of the malicious content and improve site performance for global victims. Users who visited this domain should immediately revoke any permissions granted to connected wallets or applications. If credentials, private keys, or seed phrases were entered, transfer all assets to a new, secure wallet and monitor accounts for unauthorized transactions. Check browser extensions and connected applications for any suspicious activity, as phishing sites often attempt to install malware or backdoors. Report the incident to the targeted platform (Aave) and relevant security teams to aid in takedown efforts. Always verify domain authenticity by cross-referencing official sources before interacting with any financial or cryptocurrency-related site.
网络安全情报
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Hagezi Threat Feed | solana-rpc.publicnode.com |
malicious | Sinkholed |
威胁响应 Pipeline
公共封禁名单状态
已保存的截图
域名情报
技术细节DNS、SSL SAN、时间戳
ICANN OVERSIGHT
Registration: arweave.net
认证和 RAA 背景
认证和 RAA 背景
Registrar accreditation and DNS abuse obligations
For the registrable domain arweave.net behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
VirusTotal 分析
证据与外部报告
PD-20260607-735C5B Recipient: abuse@datacamp.co.uk 您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。