brervis.network
“Brevis Network”
brervis.network — 内容不可用. 品牌冒充:Across; 诈骗类型:Wallet/seed Phishing. 证据摘要: VirusTotal 6/93 (alphaMountain.ai, CyRadar, Forcepoint ThreatSeeker, Fortinet, Gridinsoft); URLQuery 1 alert; Spamhaus DBL_PHISH; 4 external blocklist matches; PhishDestroy score 100/100. 注册商: NiceNIC.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
证据摘要
Analysis of the domain brervis.network indicates it was actively used for wallet and seed-phrase phishing targeting users of the Across protocol. The domain, created on February 21, 2026, was registered through NiceNIC International Group Co., Limited and hosted behind Cloudflare IP 188.114.97.3 (AS13335, United States). At the time of assessment on July 24, 2026, the site was offline, returning no active HTTP response. Security vendors detected malicious activity on this domain: six of the 93 engines on VirusTotal flagged it as harmful.
It appeared on five independent blocklists, including PhishDestroy, ScamSniffer, Polkadot, Enkrypt, and Codeesura. Gridinsoft assigned a trust score of 0 out of 100, reflecting high confidence in its malicious classification. The page title, 'Brevis Network', does not match the known branding of Across, though the domain was explicitly linked to Across impersonation in threat intelligence sources. No SSL certificate was present, increasing the likelihood of interception or tampering.
Nameservers were Cloudflare-hosted (major.ns.cloudflare.com and teagan.ns.cloudflare.com), a common pattern in phishing infrastructure due to the provider's privacy and proxy services. While the domain is currently offline, defenders should treat any future resolution or re-registration as suspicious. Network security teams are advised to block the domain and IP at perimeter level, and wallet providers should flag any interaction with brervis.network as high-risk. End users should be warned that any prior interaction with this domain may have exposed wallet credentials or recovery phrases.
网络安全情报 Registrar context
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Quad9 DNS | brervis.network |
malicious | Sinkholed |
Forensic History & Detection Timeline
-
Cloudflare Radar Scan Mar 7, 2026 · 10:21 UTCCloudflare Radar scan registered: View Radar report.
-
Domain Status Transition Feb 28, 2026 · 03:00 UTCDomain state transitioned from alive to dead.
威胁响应 Pipeline
公共封禁名单状态
Evasion analysis
Cloaking & traffic-distribution check
Stored crawler-versus-browser observations for this host, plus a live fingerprint check for Keitaro-style traffic distribution systems.
- Stored cloaking flag
- Not observed
- 伪装评分
- 0/6
- Last cloaking scan
Scanner note: dns_error: raw=dns_error; via=local_dns_prefilter
已保存的截图 · 3 sources
域名情报
技术详情DNS、SSL SAN、时间戳
ICANN OVERSIGHT
认证和 RAA 背景
认证和 RAA 背景
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Latest Classified Outcome 2026-09-20 03:47:26 UTC
VirusTotal 分析
存档证据
社区报告
由 1 名社区成员报告;首次发现于 2026年1月7日
- 已存储报告
- 1
- 已报告的唯一 URL
- 1
证据与外部报告
PD-20260107-3E50ED Recipient: abuse@nicenic.net Abuse notice text as sent to the provider
Registrar: NICENIC International Group Co., Limited (Hong Kong (China)) Policy Violations: “Services may be used only for lawful purposes… fraud, abuse and illegal activity prohibited. Violations may result in immediate suspension.” + dedicated abuse handling and takedown Applicable Laws: Crimes Ordinance Cap.200 (Fraud), Theft Ordinance Cap.210 §16A (fraud by deception), Personal Data (Privacy) Ordinance Cap.486
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。