MALICIOUS — CRITICAL
فحص التصيد والأمان للنطاق vote-firelight.finance
vote-firelight[.]
This domain, vote-firelight.finance, poses as a legitimate digital asset protection service under the Firelight brand to execute credential phishing attacks targeting cryptocurrency users.
- VirusTotal
- 2/91
- Blocklists
- 3 · MetaMask, ScamSniffer
- التوفر
- المحتوى غير متوفر · HTTP 502
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
vote-firelight.finance — المحتوى غير متوفر (HTTP 502). انتحال العلامة التجارية: Firelight; نوع الاحتيال: Crypto Scam. ملخص الأدلة: VirusTotal 2/91 (Gridinsoft, SOCRadar); URLScan malicious verdict; 3 external blocklist matches (MetaMask, ScamSniffer, SEAL); PhishDestroy score 74/100. مسجّل النطاق: PDR.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
Evidence Analysis
This domain, vote-firelight.finance, poses as a legitimate digital asset protection service under the Firelight brand to execute credential phishing attacks targeting cryptocurrency users. The site mimics security infrastructure, presenting itself as a "Protection Layer for Digital Assets" to deceive victims into entering wallet credentials, private keys, or recovery phrases. Analysis indicates the domain is designed to harvest sensitive authentication data, which attackers can then use to drain digital wallets or gain unauthorized access to blockchain-based assets. The threat is particularly elevated due to the domain’s use of technical obfuscation and infrastructure commonly associated with legitimate crypto security providers. Infrastructure analysis reveals multiple high-confidence indicators of malicious activity. The domain was registered on April 30, 2026, through PDR Ltd. d/b/a PublicDomainRegistry.com, a registrar frequently exploited for fraudulent schemes. It resolves to the IP address 104.21.53.212, which is protected by Cloudflare, a service often leveraged to mask the true origin of phishing sites. The domain appears on four security blocklists, including MetaMask, PhishDestroy, SEAL, and ScamSniffer, and is flagged by 2 out of 95 security vendors on VirusTotal. Detected technologies include Framer Sites, React, and Cloudflare Browser Insights, further confirming the use of modern web frameworks to enhance the site’s credibility while evading detection. Users who visited vote-firelight.finance should immediately revoke any permissions granted to the site via wallet connections or browser extensions. If credentials, private keys, or recovery phrases were entered, affected wallets must be transferred to new, secure addresses, and all associated devices should be scanned for malware. Monitor transaction histories for unauthorized activity and report the incident to relevant blockchain security teams. Given the domain’s current offline status, users should remain vigilant for similar phishing attempts, particularly those impersonating crypto security services, and verify all URLs against official sources before interacting with them.
Stored source results
Recorded verdicts and infrastructure observations for this domain.
نطاق تغطية البيانات12 recorded checks
استخبارات أمن الشبكات
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
لقطة محفوظة
معلومات النطاق
التفاصيل الفنيةDNS، أسماء المجال البديلة (SAN) في بروتوكول SSL، الطوابع الزمنية
ICANN OVERSIGHT
الاعتماد وسياق RAA
الاعتماد وسياق RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
التقنيات · 5 identified
Framer is a no-code web design platform for designing and publishing responsive websites.
www.framer.com ثقة 100٪React is an open-source JavaScript library for building user interfaces or UI components.
reactjs.org ثقة 100٪Cloudflare Browser Insights is a tool that measures the performance of websites from the perspective of users.
www.cloudflare.com ثقة 100٪Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com ثقة 100٪HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org ثقة 100٪تحليل VirusTotal
الأدلة والتقارير الخارجيةIndependent lookups and source reports
PD-20260430-9D8B34 Recipient: abuse@publicdomainregistry.com Victim safety and official reportingImmediate actions and verified reporting channels
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.