app[.]aawve[.]com
“Aave - Open Source Liquidity Protocol”
证据摘要
Analysis of the domain app.aawve.com indicates a wallet and seed-phishing campaign targeting users of the Aave decentralized finance protocol. The domain was registered on February 21, 2026, and resolved to the IP address 217.114.42.73, hosted under AS57724 (DDOS-GUARD LTD) in Russia. The page title, 'Aave - Open Source Liquidity Protocol,' directly mirrors the branding of the legitimate Aave platform, confirming intent to deceive users into disclosing sensitive credentials. Infrastructure review reveals the domain was flagged by 12 of 93 security vendors on VirusTotal, suggesting moderate detection coverage at the time of assessment.
It also appeared on two independent security blocklists, including PhishDestroy and ScamSniffer, further validating its malicious classification. The SSL certificate, issued under the R10 root, does not provide meaningful trust signals, and the Gridinsoft trust score of 0/100 reinforces the domain's high-risk status. As of July 23, 2026, the domain is offline, though historical resolution and detection data remain relevant for retrospective threat hunting. Defenders should treat any prior resolution to 217.114.42.73 or association with the seed identifier 'dceb21' as indicators of compromise.
Organizations are advised to block the domain, IP, and associated SSL certificate across security gateways and endpoint protection systems. Given the targeting of cryptocurrency wallets, users who may have interacted with the domain should be directed to revoke active sessions and monitor for unauthorized transactions. The exact phishing kit or payload delivery mechanism remains unconfirmed, as no forensic artifacts from the live page are currently available for analysis.
Data Coverage
威胁响应 Pipeline
阻止列表覆盖
监控中的外部数据源 10 个 · 已存快照 2026年8月11日
社区报告
由 1 名社区成员报告;首次发现于 2025年7月13日
- 已存储报告
- 1
- 已报告的唯一 URL
- 1
取证情报
VirusTotal 分析
仿冒域名
已存储 95 个仿冒域名
显示全部(83)
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。
检查任意域名
使用存储的阻止列表、WHOIS、DNS 和公共扫描证据进行威胁分析
立即扫描举报网络钓鱼
将可疑域名提交至我们的威胁数据库——保护社区
报告实时威胁动态
最近的网络钓鱼报告和观察到的可用性变化
监控