voting-hyperlend.finance
“HyperLend”
voting-hyperlend.finance is a crypto drainer phishing site impersonating HyperLend. Detected by 8/95 VirusTotal vendors, registered via NiceNIC International.
The detailed PhishDestroy AI analysis below remains in English to preserve the original forensic record.
Evidence Summary
This domain, voting-hyperlend.finance, operates as a crypto drainer phishing site designed to impersonate the legitimate HyperLend platform. The site targets users by presenting a fraudulent interface that mimics the appearance of a decentralized finance (DeFi) lending service. Once users connect their cryptocurrency wallets, the site executes unauthorized transactions, draining funds from the victim’s account without consent. The threat is classified as a crypto drainer due to its direct financial exploitation mechanism, which bypasses traditional credential theft in favor of immediate asset theft via malicious smart contract interactions. Analysis indicates multiple technical indicators supporting the malicious classification of this domain. The domain was registered on February 21, 2026, through NiceNIC International Group Co., Limited, a registrar frequently associated with high-risk domains. It resolves to the IP address 188.114.97.3 and is flagged by 8 out of 95 security vendors on VirusTotal. Additionally, the domain appears on 4 distinct security blocklists and is actively blocked by wallet security tools such as MetaMask and ScamSniffer. The SSL certificate is issued by Google Trust Services, and the site employs Cloudflare for hosting, which may obscure its true origin and complicate takedown efforts. The Gridinsoft trust score of 0/100 further corroborates its malicious intent. Users who have visited voting-hyperlend.finance or interacted with the site should immediately disconnect any connected wallets and revoke all smart contract approvals associated with the domain. It is critical to audit wallet transactions for unauthorized transfers and report the incident to relevant blockchain security platforms. If funds were transferred, victims should document all transaction hashes and contact their wallet provider for potential recovery options. Additionally, users should monitor their accounts for signs of further compromise and consider resetting credentials for any accounts linked to the wallet. Avoid re-engaging with the domain or any associated URLs to prevent additional exposure.
Network Security Intelligence Registrar context
Forensic History & Detection Timeline
-
Domain Status Transition Jul 27, 2026 · 00:45 UTCDomain state transitioned from dead to alive.
-
VirusTotal Detections Update Jun 27, 2026 · 00:46 UTCVirusTotal scanner detections updated from 7 to 8. Added scanner alerts: ADMINUSLabs, CRDF, Chong Lua Dao, Forcepoint ThreatSeeker. Resolved alerts: SOCRadar, Seclookup, URLQuery.
-
Cloudflare Radar Scan Mar 7, 2026 · 08:25 UTCCloudflare Radar scan registered: View Radar report.
-
Domain Status Transition Feb 27, 2026 · 07:05 UTCDomain state transitioned from alive to dead.
Threat Response Pipeline
Public Blocklist Status
Detection-evasion analysis
Cloaking suspected: scanner and visitor titles differ
Not observed
No cloaking was observed in the stored scan
Stored crawler-versus-browser observations for this host, plus a live fingerprint check for Keitaro-style traffic distribution systems.
- Stored cloaking flag
- Not observed
- Cloaking score
- 0/6
- Last cloaking scan
- Server header seen by scanner
cloudflare
Scanner note: cloudflare_ban: raw=cf_phishing_block; http=403; via=https_proxy; server=cloudflare; provider_error=cloudflare_phishing_interstitial
Provider response during scan: cloudflare_phishing_interstitial
Stored Capture · 2 sources
Domain Intelligence
Technical detailsDNS, SSL SANs, timestamps
ICANN OVERSIGHT
Accreditation and RAA context
Accreditation and RAA context
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Latest Classified Outcome 2026-09-21 02:45:59 UTC
Technologies · 3 identified
VirusTotal Analysis
Archived Evidence
Site Performance Analysis
Google PageSpeed Insights — mobile performance audit of voting-hyperlend.finance · checked Jun 27, 2026
Community reports
Reported by 1 community member, first seen Feb 12, 2026
- Stored reports
- 1
- Unique reported URLs
- 1
Evidence & External Reports
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive