portal-aave[.]co
portal-aave.co — 未验证. 品牌冒充:Aave; 诈骗类型:Brand Impersonation. 证据摘要: VirusTotal 3/91 (CRDF, Gridinsoft, SOCRadar); 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 66/100. 注册商: DYNADOT.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
PhishDestroy identifies portal-aave.co as an active brand impersonation domain targeting Aave users. This fraudulent site mimics the legitimate Aave protocol to deceive victims into entering sensitive credentials or cryptocurrency wallet information. The threat type is specifically 'brand impersonation,' leveraging the trust associated with the Aave brand to execute credential harvesting or cryptocurrency draining schemes. No advanced drainer kit artifacts, such as obfuscated JavaScript or known malware payloads, have been observed during initial analysis, suggesting a basic but effective phishing landing page designed to harvest user inputs.
This domain was flagged with a VirusTotal detection score of 0/95, indicating it is not yet widely recognized as malicious by antivirus engines. It resolves to IP address 188.114.96.3, registered through Dynadot Inc on April 26, 2026. The domain utilizes a Let's Encrypt SSL certificate, which does not inherently indicate legitimacy, as threat actors frequently exploit free certificate authorities to appear more authentic. As of this report, the domain remains unblocked by Google Safe Browsing (GSB) and has not been listed on major threat intelligence blocklists, allowing it continued availability on the open web.
The current status of this domain is 'active,' and it remains under investigation by threat intelligence teams. While the immediate risk is assessed as 'under_investigation,' the lack of detections and blocklisting suggests a window of opportunity for malicious operations. Users are strongly advised to avoid interacting with portal-aave.co or any similar Aave impersonation domains. Security teams should monitor this domain for escalation in malicious activity and consider proactive blocking based on domain and IP indicators. Remaining risk includes potential credential theft, financial loss, or further compromise of cryptocurrency assets through social engineering and impersonation tactics.
威胁响应 Pipeline
公共封禁名单状态
VirusTotal 分析
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。