# vote-etherfi.app — SUSPICIOUS > Discover how vote-etherfi.app impersonated Etherfi in a low-risk phishing attempt. Learn key details and current status on PhishDestroy. ## Summary PhishDestroy identifies vote-etherfi.app as a phishing domain impersonating the Etherfi platform. Classified under generic phishing, it aimed to deceive users by mimicking the legitimate Etherfi brand, as indicated by the page title. The domain was registered on March 10, 2026, suggesting recent malicious activity targeting cryptocurrency users. Technical analysis reveals the domain resolved to IP address 172.67.205.20 and appeared on four different security blocklists, confirming suspicion among security communities. Despite this, only one out of 95 VirusTotal security vendors flagged the domain, indicating a low detection rate at the time of analysis. These indicators suggest the campaign was emerging or limited in scope. Currently, vote-etherfi.app is offline and no longer resolving, reflecting a successful takedown or abandonment by threat actors. Users are advised to remain cautious with similar domains and verify authenticity when interacting with crypto-related services. PhishDestroy continues monitoring such domains to provide timely threat intelligence. ## Threat Details - Verdict: SUSPICIOUS - Site status: dead (HTTP 403) - Page title: Etherfi ## Domain Intelligence - Registered: 2026-03-10 23:07:01 - IP: 172.67.205.20 - IP Country: US - IP City: San Francisco - IP Org: AS13335 Cloudflare, Inc. - Nameservers: nancy.ns.cloudflare.com rayden.ns.cloudflare.com - SSL Issuer: Let's Encrypt / E8 ## Detection Status - VirusTotal: 1 vendors flagged Vendors: ["SOCRadar"] - Google Safe Browsing: clean - Blocklists: 4 hits Lists: ["PhishDestroy", "MetaMask", "SEAL", "Enkrypt"] ## Evidence - Screenshot: https://i.ibb.co/Nd2579W8/727d0993872d.png - Cloudflare Radar: https://radar.cloudflare.com/scan/4c1135ce-fbf0-4e36-9b8d-363a8b877796 - PhishDestroy: https://phishdestroy.io/domain/vote-etherfi.app/ - LLM endpoint: https://phishdestroy.io/domain/vote-etherfi.app/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/vote-etherfi.app/ Last updated: 2026-03-19