defiapp[.]app
“DeFiApp dot App: premium domain name (Buy now) - defiapp.app”
证据摘要
This domain, defiapp.app, is identified as a brand impersonation threat targeting Foundation, a known entity in the decentralized finance (DeFi) ecosystem. The site mimics legitimate Foundation platforms to deceive users into engaging with fraudulent applications, potentially leading to unauthorized access to cryptocurrency wallets or the execution of malicious smart contracts. Such impersonation tactics are commonly employed to distribute crypto drainers, which automatically siphon digital assets from victims' wallets upon interaction with the malicious site. The risk is elevated due to the domain's association with DeFi, a high-value target for threat actors seeking to exploit users' trust in blockchain-based applications.
Analysis of defiapp.app reveals multiple technical indicators supporting its classification as malicious. The domain is flagged by 14 out of 95 security vendors on VirusTotal, indicating broad consensus on its harmful nature. It was registered on March 01, 2023, through 1API GmbH, a registrar frequently utilized for both legitimate and malicious domains. The domain resolves to the IP address 165.22.123.139 and is currently listed on one security blocklist, further corroborating its association with phishing infrastructure. Detected technologies include Apache HTTP Server, jQuery UI, and jQuery, which are commonly used in both benign and malicious web applications but provide no inherent legitimacy in this context. The page title, 'DeFiApp dot App: premium domain name (Buy now) - defiapp.app,' suggests an attempt to appear as a legitimate domain marketplace, a tactic often used to delay detection while the infrastructure is prepared for malicious use.
Users who have visited defiapp.app or interacted with its content should take immediate remedial actions to mitigate potential risks. Disconnect any cryptocurrency wallets linked to the site and revoke permissions for any suspicious smart contracts using tools like Etherscan or blockchain explorers. Monitor wallet activity for unauthorized transactions and consider transferring assets to a new wallet if compromise is suspected. Report the domain to relevant security platforms and blockchain communities to prevent further exploitation. Additionally, scan local devices for malware, as interaction with phishing sites may lead to secondary infections. Exercise caution with future DeFi-related communications, verifying domain authenticity and using hardware wallets for enhanced security.
Data Coverage
威胁响应 Pipeline
阻止列表覆盖
监控中的外部数据源 10 个 · 已存快照 2026年8月11日
检测时间线
-
VirusTotal
8 → 14
已保存的截图
域名情报
技术详情DNS、TLS 名称和时间戳
ICANN OVERSIGHT
认证和 RAA 背景
认证和 RAA 背景
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
技术
识别出 3 项高置信度技术
VirusTotal 分析
网站性能分析
Google PageSpeed Insights — mobile performance audit of defiapp.app · checked Jun 27, 2026
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。
检查任意域名
使用存储的阻止列表、WHOIS、DNS 和公共扫描证据进行威胁分析
立即扫描举报网络钓鱼
将可疑域名提交至我们的威胁数据库——保护社区
报告实时威胁动态
最近的网络钓鱼报告和观察到的可用性变化
监控