Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is abuse@godaddy.com.
The latest stored availability evidence still shows the domain reachable; 6 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
approvedexperiencestraveller[.]co
“Approved - Travel Experiences”
approvedexperiencestraveller.co — 隐形 · 可达. 诈骗类型:Investment Scam. 证据摘要: VirusTotal 2/91 (CRDF, Gridinsoft); cloaking observed; PhishDestroy score 56/100. 注册商: GoDaddy.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
This domain, approvedexperiencestraveller.co, is identified as a brand impersonation threat targeting users of the Aave decentralized finance platform. The site masquerades as an official Aave service under the guise of 'Approved - Travel Experiences,' a deceptive page title designed to mislead victims into interacting with fraudulent smart contracts or disclosing sensitive credentials. Given the domain's association with Aave—a high-value target in the cryptocurrency sector—this campaign likely aims to deploy crypto drainers or harvest wallet recovery phrases, posing significant financial risk to visitors. Analysis indicates the domain was registered on February 21, 2026, through GoDaddy.com, LLC, a registrar frequently exploited for malicious infrastructure due to its accessibility. The domain resolved to the IP address 188.114.97.3 and employed an SSL certificate issued by Google Trust Services, a common tactic to lend legitimacy to phishing sites. Despite its deceptive appearance, the domain appears on only one security blocklist and has evaded broader detection, with 0 out of 95 engines on VirusTotal flagging it as malicious. Additional infrastructure analysis reveals the use of Node.js, React, Next.js, and Nginx, technologies consistent with modern phishing frameworks designed to mimic legitimate web applications. Users who visited approvedexperiencestraveller.co should immediately revoke any connected wallet permissions via a blockchain explorer or dedicated revocation tool. All credentials or recovery phrases entered on the site must be considered compromised and should be migrated to new, secure wallets. Monitor linked accounts for unauthorized transactions and report the domain to relevant threat intelligence platforms to aid in broader detection efforts. Due to the domain's recent creation date and limited blocklist presence, heightened vigilance is advised for similar campaigns targeting Aave or other decentralized finance platforms.
威胁响应 Pipeline
公共封禁名单状态
所用技术 · 10 identified
JavaScript runtime built on Chrome V8 engine for server-side development.
JavaScript library for building user interfaces with component-based architecture.
Payment processor — credit card and alt-payment acceptance.
stripe.comHigh-performance HTTP server and reverse proxy, known for stability and low resource usage.
React framework for production with hybrid static and server rendering.
Tag management system for deploying marketing and analytics tags.
tagmanager.google.comWeb analytics service tracking website traffic and user behavior.
marketingplatform.google.comConversion-tracking pixel by Meta — logs page views and custom events to Facebook/Instagram ad accounts.
www.facebook.comModule bundler for modern JavaScript applications.
VirusTotal 分析
存档证据
网站性能分析
Google PageSpeed Insights — mobile performance audit of approvedexperiencestraveller.co · checked Jun 27, 2026
证据与外部报告
PD-20260211-ABA422 Recipient: abuse@godaddy.com 您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。