xn--ve-6kca[.]xn--mppshbrgh-0yhcd7oie7a980aha3153kdaj[.]gho-vault[.]eu[.]com
“Aave - Open Source Liquidity Protocol”
xn--ve-6kca.xn--mppshbrgh-0yhcd7oie7a980aha3153kdaj.gho-vault.eu.com — 未验证. 品牌冒充:Genericcrypto; 诈骗类型:Brand Impersonation. 证据摘要: VirusTotal 2/91 (Gridinsoft, LevelBlue); URLScan malicious verdict; PhishDestroy score 56/100. 注册商: Instra.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
The domain xn--ve-6kca.xn--mppshbrgh-0yhcd7oie7a980aha3153kdaj.gho-vault.eu.com was observed hosting content titled "Aave - Open Source Liquidity Protocol," indicating a brand‑impersonation phishing attempt targeting users of the Aave protocol. The domain was created on 21 February 2026 and is registered through Instra Corporation Pty Ltd. Its authoritative name servers are ns1.centralnic.net, ns2.centralnic.net, ns3.centralnic.net, and ns4.centralnic.net. DNS resolution points to IP address 172.67.214.171, which belongs to AS13335 Cloudflare, Inc. in the United States.
SSL certificate information lists the issuer identifier "WE1," confirming that the site employed TLS, though certificate details do not provide additional safety signals. VirusTotal reports that the domain was scanned by 93 security vendors, none of which raised a detection; the report explicitly notes that the lack of detections should not be interpreted as evidence of benign intent. The domain appears on a single security blocklist and is currently blocked by the PhishDestroy service, confirming external recognition of malicious activity.
At the time of reporting (24 July 2026) the site is offline, which limits real‑time content inspection, but the existing metadata already establishes a credible phishing infrastructure. Defenders should add the domain and its associated IP address to network deny lists, monitor for future DNS re‑registration, and enforce email filtering rules that flag messages referencing the Aave brand. Continuous telemetry from DNS sensors and periodic re‑scans of the IP host are recommended to detect any resurgence of the campaign.
威胁响应 Pipeline
公共封禁名单状态
VirusTotal 分析
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。