跳转到安全报告
⚠️
该域名已被标记为恶意域名
安全引擎报告检测:4。 请格外小心——不要输入凭据或个人信息。
域安全和威胁情报

distribution-ethena[.]fi

“Ethena”

威胁判定 65/100 证据评分
可用性 未验证 当前可达性未经验证
病毒检测总数:4/95 URLQuery threat systems: 1 alert 诈骗类型:Crypto Scam
2026年2月26日 CDN
报告概览

distribution-ethena.fi — 未验证. 诈骗类型:Crypto Scam. 证据摘要: VirusTotal 4/95 (CRDF, Ermes, Gridinsoft, Kaspersky); URLQuery 1 alert; PhishDestroy score 65/100.

为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。

证据摘要
HIGH
Ref
68EC5655
评分
65/100

The site distribution-ethena.fi displays the page title "distribution-ethena.fi | 522: Connection timed out" and is classified as a Crypto Scam. This domain impersonates the Ethena brand, likely attempting to deceive users into interacting with a fraudulent cryptocurrency distribution scheme. The primary threat is financial loss, as victims may provide credentials or send funds to the site under the false pretense of a legitimate token distribution.

Technical analysis shows that distribution-ethena.fi was created on 2026-02-21. It is hosted on IP address 2a06:98c1:3120::3, associated with AS13335 Cloudflare, Inc., and located in the United States. The domain uses nameservers junade.ns.cloudflare.com and maya.ns.cloudflare.com. Its SSL certificate is issued by Google Trust Services / WE1. VirusTotal reports 4 out of 95 security vendors flagging the site as malicious, with detections from CRDF, Ermes, Gridinsoft, and Kaspersky. It appears on 1 blocklist.

The site is currently DOWN/OFFLINE and has a domain risk score of 56, indicating a moderate to high threat level. Due to its offline status, immediate active risk is reduced, but the domain remains a potential vector for future attacks if reactivated.

VirusTotal
VirusTotal
4 det.
URLQuery
URLQuery
1 threat alert
URLScan
URLScan
TLS 证书
已过期或未验证 -66d
年龄
6 mo
观测状态
未验证
PhishDestroy
DestroyList
已列入
数据覆盖范围 VirusTotal 4 / 95 URLQuery 1 threat-system alert PhishStats 未检查 OTX no community references CF雷达 scan completed URLScan capture 存储的报告 URLScan verdict 无可用判定 DNS 阻断 未检查 TLS 已过期或未验证 WHOIS 6 mo old 屏幕截图 3 captures · 3 sources 重定向链 未探查
网络安全情报
Threat Detection Systems 1 alert
Detection System Indicator Verdict Alert
DNS0 Zero distribution-ethena.fi malicious Sinkholed

威胁响应 Pipeline

发现
Checks
Reports
可用性
9/11

公共封禁名单状态

已保存的截图

域名情报

域名
Wallet IoCs 1 format-validated 0xF99d0E4E3435cc9C9868D1C6274Df…
Telegram IoCs 1 extracted https://t.me/ethena_labs
服务器 / ASN cloudflare · AS13335 CLOUDFLARENET, US
IP Context Cloudflare shared edge origin IP hidden Edge-IP 声誉不属于此域。
IP 地址 2a06:98c1:3120::3 CDN
地理位置US San Francisco, US
网络AS13335 · Cloudflare, Inc.
源 IP 隐藏在 CDN 代理后面。边缘地址的反向 IP 结果包含不相关的租户;查找源头需要被动 DNS 或证书透明数据。
注册信息创建 2026年2月21日 (173d)
技术细节DNS、SSL SAN、时间戳
首次发现2026年2月26日
DOM Analysisanalyzed 2026年7月27日score 0/100
IoC Extractionscanned 2026年7月29日1 wallet · 1 Telegram IoCs
域名服务器maya.ns.cloudflare.com
TLS Fingerprint
TLS Observationvalid from 2026年3月11日scanned 2026年3月15日
页面标题
Ethena
TLS 证书
已过期或未验证 · 颁发者 Google Trust Services / WE1
所用技术 · 2 identified
Cloudflare
CDN

Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.

www.cloudflare.com 置信度 100%
HTTP/3
Miscellaneous

HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.

httpwg.org 置信度 100%
Detected via Cloudflare Radar · Wappalyzer engine
举报此域名 提交证据,帮助保护他人

VirusTotal 分析

4 / 95 安全供应商标记了该域
View on VT
Last analyzed
CRDF
Ermes
Gridinsoft
卡巴斯基

证据与外部报告

您是否受到本网站的影响?

If credentials were compromised, report immediately. Do not engage with recovery scammers.

如果您与此域交互、输入个人信息或连接加密货币钱包,请立即采取行动。以下资源可帮助您报告事件并保护自己。

欧洲刑警组织
查找您所在欧盟国家/地区的官方报告渠道
National police directory
警惕“数据恢复”诈骗! 犯罪分子可能会冒充调查员、律师或追债员再次联系受害者。 请勿支付预付费用或共享凭证。 没有任何合法服务可以保证恢复被盗的加密货币。 了解有关康复欺诈的更多信息 →

向当地主管部门报告

选择您所在的国家/地区以获取 官方网络犯罪联系人创建投诉草稿 →

97个国家目录
AI辅助草稿——事件详细信息由AI提供商处理 自行审核并提交

检查任意域名

使用存储的阻止列表、WHOIS、DNS 和公共扫描证据进行威胁分析

立即扫描

举报网络钓鱼

将可疑域名提交至我们的威胁数据库——保护社区

报告

实时威胁动态

最近的网络钓鱼报告和观察到的可用性变化

监控

随时掌握最新信息,确保安全

请实时监控威胁,或者如果您认为这是误报,请对该条目提出异议

实时威胁动态 对该列表提出异议

针对受害者的建议与指导

据估计 $51 billion 于2024年流入非法加密货币钱包(source). 如果你曾与 distribution-ethena.fi — 立即行动。

我应该立即采取什么措施?
紧急
  • 撤销令牌授权 — use revoke.cash 撤销授予恶意智能合约的访问权限
  • 转移剩余资金 迁移到一个全新的钱包。该受损钱包已不再安全
  • 更改所有密码 — 电子邮件、Exchange 账户,以及任何使用同一密码的账户
  • 启用双因素认证 使用身份验证器应用(而非短信)。禁用基于短信的恢复功能
  • 冻结卡片 如果您在钓鱼网站上输入了银行信息
我应该为报告收集哪些信息?
联邦调查局(FBI)指南

联邦调查局,其中最重要的细节是交易数据:

  • 加密货币地址 — 诈骗分子的钱包(例如, 0x5856...35985)
  • 金额及加密货币类型 — 确切金额(例如:1.02345 ETH、0.5 BTC、500 USDT)
  • 交易 ID(哈希值) — 唯一的区块链交易标识符
  • 确切日期和时间 — 每笔交易的详情以及与诈骗者的首次接触
  • 屏幕截图 — 诈骗网站、聊天消息、电子邮件、钱包交易、社交媒体
  • 所有网址和域名 诈骗者使用的(包括 distribution-ethena.fi)
  • 通信 — 诈骗者使用的电子邮件、短信、电话号码、用户名

即使你并不了解所有细节—— 不管怎样都要提交报告. 即使信息不完整,对调查仍有帮助。

我应该向哪里举报这起诈骗?
  • 联邦调查局(FBI)IC3 — 互联网犯罪投诉中心(美国联邦举报渠道)
  • 欧洲刑警组织 — 欧洲网络犯罪报告(欧盟)
  • Chainabuse — 在各交易所和平台上标记诈骗钱包
  • 您的加密货币交易所 — notify its fraud team immediately; it may be able to preserve records or restrict funds held on its platform
  • 当地警方 — 即使无法立即采取行动,也能留下正式记录

A report is not a guarantee of recovery or investigation, but prompt, accurate transaction data can help authorities and service providers trace the incident.

加密货币诈骗通常是如何运作的?
  • 虚假网站 — 与正规网站完全一致的克隆网站,仅域名略有改动
  • 恶意批准 — “连接钱包”的提示会使攻击者获得无限的代币消费权限
  • 猪的屠宰 — 通过Telegram/WhatsApp/交友软件花数周时间建立信任,随后钱被骗走
  • 退款诈骗 — fraudsters pose as recovery agents and demand upfront fees. Never share a seed phrase or pay before independently verifying the provider
  • 虚假广告与空投 — 谷歌/社交媒体广告和“免费代币”优惠会导致钱包被掏空
  • 利用人工智能实施的诈骗 — 深度伪造、自动化网络钓鱼以及人工智能生成的网站,使得欺诈行为更难被察觉
将来我该如何保护自己?
  • 使用硬件钱包 (Ledger、Trezor)。切勿在浏览器钱包中存储大额资金
  • 将官方网站添加到书签 — 切勿点击来自电子邮件、私信或广告中的链接
  • 阅读每项批准 — 签名前请验证权限。拒绝无限制的批准
  • 验证域名 — 查看 PhishDestroy 在进行互动之前,请检查HTTPS、拼写和域名注册时间。
  • “好得令人难以置信”=骗局 — 保证收益、名人代言、紧迫的截止日期
HTML · IFRAME

嵌入此报告

在您的网站或博客上分享此威胁情报

embed.html
<iframe
  src="https://phishdestroy.io/zh/embed/domain/distribution-ethena.fi"
  title="PhishDestroy threat report for distribution-ethena.fi"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>