# votes-ondofinance.xyz — SUSPICIOUS > Beware: votes-ondofinance.xyz is a crypto drainer impersonating Do Finance. Verify this domain on PhishDestroy before proceeding. ## Summary PhishDestroy identifies votes-ondofinance.xyz as an active crypto drainer phishing domain registered to harvest cryptocurrency from unsuspecting users. This domain poses an elevated risk due to its malicious intent and recent deployment. This domain was flagged by VirusTotal with 1 out of 95 security vendors detecting it, indicating low but present detection. Registered through PDR Ltd. d/b/a PublicDomainRegistry.com on March 29, 2026, it resolves to IP 188.114.96.3 and utilizes a Let's Encrypt SSL certificate to appear legitimate. The domain's recent creation date and low detection rate suggest it may evade traditional security measures temporarily. Users should avoid interacting with this domain entirely. If you suspect exposure, transfer any remaining funds to a new wallet immediately and revoke any connected permissions. Report the domain to PhishDestroy for further analysis and community protection. ## Threat Details - Verdict: SUSPICIOUS - Site status: unknown (HTTP ?) ## Domain Intelligence - Registered: 2026-03-29 17:47:22 - Registrar: PDR Ltd. d/b/a PublicDomainRegistry.com - IP: 188.114.96.3 ## Detection Status - VirusTotal: 1 vendors flagged - Google Safe Browsing: clean - Blocklists: 0 hits ## Evidence - Cloudflare Radar: https://radar.cloudflare.com/scan/49f9490d-6a56-4d8c-b811-d0bb44537425 - PhishDestroy: https://phishdestroy.io/domain/votes-ondofinance.xyz/ - LLM endpoint: https://phishdestroy.io/domain/votes-ondofinance.xyz/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/votes-ondofinance.xyz/ Last updated: 2026-03-29