Observed role
Malware delivery infrastructure
Indicator that identifies a malware distribution server (payload delivery)
Indicator investigation
Loading the current evidence view. Navigation and account controls remain available.
Loading verdict, provenance, relationships and sightings.
Indicator
Type domain · source ScamSniffer Scam Domains
KNOWN MALWARE — Defi-phish
Domain investigation
The warehouse identifies this domain as Unknown malware. It was registered 2 months ago. 1 stored citation support the local history. Domain ownership, hosting, and content can change, so attribution remains bounded to the cited observation.
Observed role
Malware delivery infrastructure
Indicator that identifies a malware distribution server (payload delivery)
Registration
2 months ago
2026-06-25 · Dynadot Inc
Certificate history
Not established
Certificate Transparency lookup did not complete.
Current DNS
2 current IPv4 addresses
188.114.96.3, 188.114.97.3 · observed 2026-08-07
Corpus evidence
1 connectors · 1 citations
Generic co-tags were excluded to avoid false relationships.
Observation window
2026-07-25 → 2026-09-05
First and last appearance in the local corpus, not global activity dates.
Findings stay bounded to named sources and observable infrastructure.
Domain indicator: app.compensationaave.cc
Neighborhood topology. Open the graph for interactive pivots.
Loading connected indicators, reports and entities.
High-signal pivots without leaving the thread you started in search.
Structured pivots from local graph context.
Full investigation canvas with neighbor expansion.