The domain vote-flap.co was created on July 29, 2026 and is registered through Dynadot Inc. It is delegated to Cloudflare’s authoritative nameservers jo.ns.cloudflare.com and lex.ns.cloudflare.com, and resolves to the IP address 172.67.189.121, a Cloudflare‑owned host. Infrastructure analysis shows no unique hosting characteristics beyond the shared Cloudflare edge, which can obscure the ultimate backend server. The domain is currently listed on three public security blocklists and is explicitly blocked by the PhishDestroy, MetaMask, and SEAL filtering services. Google Safe Browsing has classified the site under the “social engineering” category, indicating it is being used to trick users into disclosing credentials or personal data. A VirusTotal scan records a single detection out of ninety‑one scanned engines, confirming that at least one security product has identified malicious behavior associated with the domain.
No publicly available SSL certificate details, HTTP status codes, page title, or additional evidence links have been reported, so the exact content and delivery mechanism remain unverified. The lack of visible page metadata suggests that the site may be employing rapid content changes or temporary landing pages to evade static analysis. Given the recent registration date, the active status, and the convergence of multiple independent detections, the domain should be treated as a high‑risk credential‑harvesting vector.
Defenders are advised to add vote-flap.co and its resolved IP 172.67.189.121 to perimeter blocklists, enforce DNS sink‑hole rules for the domain, and monitor outbound traffic for any attempted connections. Continuous re‑evaluation with VirusTotal and other sandbox services is recommended, as the threat actor may evolve the payload or host additional malicious resources behind the same Cloudflare front.