MALICIOUS — CRITICAL
Phishing- und Sicherheitsprüfung für vote-8zf.pages.dev
vote-8zf[.]
Analysis of vote-8zf.pages.dev shows a newly registered site (May 11 2026) hosted on Cloudflare Pages and serving content over HTTPS with a Google Trust Services certificate.
- VirusTotal
- 3/91
- Blocklists
- 3 · MetaMask, ScamSniffer
- Verfügbarkeit
- Letzter bekanntermaßen aktiv · HTTP 200
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
vote-8zf.pages.dev — Letzter bekanntermaßen aktiv (HTTP 200). Betrugstyp: Crypto Drainer. Zusammenfassung der Beweislage: VirusTotal 3/91 (alphaMountain.ai, Gridinsoft, LevelBlue); 3 external blocklist matches (MetaMask, ScamSniffer, SEAL); PhishDestroy score 84/100. Registrar: Cloudflare Pages.
Die ausführliche Analyse von PhishDestroy AI bleibt auf Englisch, damit der ursprüngliche forensische Bericht unverändert bleibt.
Evidence Analysis
Analysis of vote-8zf.pages.dev shows a newly registered site (May 11 2026) hosted on Cloudflare Pages and serving content over HTTPS with a Google Trust Services certificate. The page title advertises “Save, Grow, Spend. Do more with your crypto | ether.fi”, matching a crypto‑drainer campaign that attempts to lure cryptocurrency users into authorizing transfers. The domain resolves to IP 188.114.97.3, an address owned by Cloudflare, Inc. in Canada. Infrastructure indicators include a Gridinsoft trust score of 0/100 and inclusion on four external blocklists. Multiple anti‑phishing feeds (PhishDestroy, MetaMask, SEAL, ScamSniffer) have already flagged the host as malicious, and the site returns HTTP 200, confirming active content delivery. Defenders should treat vote‑8zf.pages.dev as a high‑risk indicator. Network monitoring should block outbound connections to the resolved IP and any future DNS resolutions of the domain. Email gateways and web proxies ought to enforce deny‑list rules for the domain and its parent zone (pages.dev). Because the site leverages a legitimate SSL certificate, TLS inspection may be required to detect the malicious payload. Continuous watch for new sub‑domains under pages.dev is advisable, given the ease of generating additional clones on the same hosting platform. At present, no further technical artifacts such as payload hashes or command‑and‑control endpoints have been disclosed, so threat‑intel teams should prioritize collection of request/response logs should the domain be accessed.
Stored source results
Recorded verdicts and infrastructure observations for this domain.
Datenabdeckung12 recorded checks
Pipeline zur Reaktion auf Sicherheitsbedrohungen
Status der öffentlichen Sperrliste
Domain-Intelligenz
Technische DetailsDNS, SSL-SANs, Zeitstempel
VirusTotal-Analyse
Nachweise und externe BerichteIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Wenn Sie Kontoanmeldeinformationen, persönliche oder Zahlungsinformationen eingegeben oder eine Datei von dieser Domain heruntergeladen haben, ergreifen Sie sofort Maßnahmen. Nachfolgend finden Sie Ressourcen, die Ihnen helfen, den Vorfall zu melden und sich zu schützen.
Melden Sie sich bei Ihren örtlichen Behörden
Wählen Sie Ihr Land aus, um Offizielle Kontakte im Bereich Cyberkriminalität oder einen Beschwerdeentwurf erstellen → zu erhalten.