MALICIOUS — HIGH
byvotes[.]space
3 security engines flagged the domain; 2 public blocklists listed it (MetaMask, SEAL); the latest stored check returned HTTP 502.
- VirusTotal
- 3 detections
- Blocklists
- 2 · MetaMask, SEAL
- التوفر
- المحتوى غير متوفر · HTTP 502
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
byvotes.space — المحتوى غير متوفر (HTTP 502). نوع الاحتيال: Crypto Drainer. ملخص الأدلة: VirusTotal 3 detections (engine total unavailable) (Ermes, Gridinsoft, SOCRadar); 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 66/100. مسجّل النطاق: Hostinger.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
Evidence Digest
byvotes.space is classified high with an evidence score of 66/100. 3 security engines flagged the domain; 2 public blocklists listed it (MetaMask, SEAL). Registered 3 May 2026 via HOSTINGER operations, UAB, hosted on 188.114.97.3 (Cloudflare, Inc., CA). The latest stored check on 9 Aug 2026 returned HTTP 502 and includes a capture. 1 outgoing abuse report is recorded, most recently on 4 May 2026.
Stored generated summary (templated)mistral · 26/06/2026
Retained for the record. This text repeats stored detection facts and is not presented as authored analysis.
This domain, byvotes.space, is identified as a crypto drainer phishing site designed to impersonate legitimate voting or polling platforms to deceive users into connecting cryptocurrency wallets. Once connected, the site executes unauthorized transactions, draining digital assets from victims' wallets without consent. The threat specifically targets users through social engineering tactics, leveraging fake voting incentives or rewards to lower suspicion and prompt wallet connections. Analysis indicates the site employs obfuscated JavaScript to interact with wallet APIs, a common technique in crypto drainer schemes to bypass basic security checks. Infrastructure analysis reveals concrete indicators of malicious activity. The domain was registered on May 03, 2026, through HOSTINGER operations, UAB, a registrar frequently associated with phishing campaigns. It resolves to the IP address 188.114.97.3 and is currently offline, though this does not mitigate prior exposure risks. Security vendors on VirusTotal flagged the domain at a rate of 3/95, while it appears on three independent security blocklists, including high-confidence threat intelligence feeds. Technologies detected include Node.js, Vue.js, and Nuxt.js, which are often used to create dynamic, interactive phishing interfaces. Additionally, the use of Cloudflare and HTTP/3 suggests an attempt to mask infrastructure and evade detection through encrypted traffic. Users who visited byvotes.space or interacted with its content should take immediate remedial actions. First, disconnect any cryptocurrency wallets that were linked to the site and revoke all active session permissions via wallet management interfaces. Monitor transaction histories for unauthorized activity and report suspicious transactions to the respective blockchain network or wallet provider. If credentials or private keys were entered, assume they are compromised and migrate assets to a new wallet with a fresh seed phrase. Scan local devices for malware using updated security tools, as phishing sites may deploy secondary payloads. Finally, report the domain to relevant security communities to aid in broader threat mitigation efforts.
نطاق تغطية البيانات12 recorded checks
استخبارات أمن الشبكات
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
لقطة محفوظة
معلومات النطاق
التفاصيل الفنيةDNS، أسماء المجال البديلة (SAN) في بروتوكول SSL، الطوابع الزمنية
ICANN OVERSIGHT
الاعتماد وسياق RAA
الاعتماد وسياق RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
التقنيات · 6 identified
Node.js is an open-source, cross-platform, JavaScript runtime environment that executes JavaScript code outside a web browser.
nodejs.org ثقة 100٪Vue.js is an open-source model–view–viewmodel JavaScript framework for building user interfaces and single-page applications.
vuejs.org ثقة 100٪Cloudflare Browser Insights is a tool that measures the performance of websites from the perspective of users.
www.cloudflare.com ثقة 100٪Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com ثقة 100٪HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org ثقة 100٪تحليل VirusTotal
تحليل أداء الموقع
Google PageSpeed Insights — mobile performance audit of byvotes.space · checked Jun 26, 2026
الأدلة والتقارير الخارجيةIndependent lookups and source reports
PD-20260504-2E147F Recipient: abuse@hostinger.com Victim safety and official reportingImmediate actions and verified reporting channels
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.