vote-mainstreet[.]finance
The domain vote-mainstreet.finance has been identified as a high-risk vector for generic phishing attacks. Analysis indicates that this domain is actively being leveraged to deceive users and harvest credentials, posing a significant risk of unauthorized access and data compromise. The infrastructure is currently online and operational, creating an ongoing threat to users who may be tricked into interacting with malicious content hosted on this domain.
Technical evidence supports the high-risk classification. VirusTotal reports that 3 out of 95 security vendors flag vote-mainstreet.finance as malicious. Furthermore, the domain is present on two independent security blocklists, reinforcing its reputation as a phishing asset. Registration records show that the domain was created on June 20, 2026, through NICENIC INTERNATIONAL GROUP CO., LIMITED, suggesting recent and intentional deployment for malicious purposes. The domain resolves to IP address 188.114.96.3 and utilizes an SSL certificate issued by Google Trust Services, which may be intended to lend a false sense of legitimacy to victims.
Users who have visited vote-mainstreet.finance or interacted with any content from this domain should immediately cease all engagement and perform comprehensive security checks. This includes changing passwords for any accounts that may have been exposed, monitoring for unauthorized activity, and updating security software. Organizations are advised to block the domain at the network level and update security awareness resources to include this active threat. Continued vigilance and prompt remediation actions are recommended to mitigate the elevated risk presented by this phishing campaign.
Network Security Intelligence Registrar context
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Hagezi Threat Feed | vote-mainstreet.finance |
malicious | Sinkholed |
Threat Response Pipeline
Public Blocklist Status
Stored Capture
Domain Intelligence
Technical detailsDNS, SSL SANs, timestamps
ICANN OVERSIGHT
Accreditation and RAA context
Accreditation and RAA context
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Latest Classified Outcome 2026-08-15 02:49:25 UTC
Technologies · 2 identified
Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100% confidenceHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% confidenceVirusTotal Analysis
Site Performance Analysis
Google PageSpeed Insights — mobile performance audit of vote-mainstreet.finance · checked Jun 28, 2026
Evidence & External Reports
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive