VirusTotal
3 / 92
“The Index — hold it, get paid in stocks”
The sent-report ledger records the first outgoing report at .
The recorded recipient is abuse@spaceship.com.
The latest stored availability evidence still shows the domain reachable; 2 days has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
3 / 92
Report stored; detailed verdict not recorded
Report2 community references
Reportprovider verdict: suspicious
Reportstored report
Report Analysis completed
ReportChecked; no threat flag recorded
ReportThe domain voting-theindexfinance.cfd was recorded on 2026-10-09 with entries on the MetaMask and SEAL blocklists, providing a dated reference for its security context. Additionally, a PageSpeed performance score of 76 was captured for this domain, offering a technical metric for review.
On 2026-10-09, voting-theindexfinance.cfd was listed on both the MetaMask and SEAL external blocklists. VirusTotal checked the domain on the same date, recording 3 detections out of 92 total scanners. OTX referenced the domain with 2 pulses, and PhishDestroy included it in its internal listing. The domain was registered with Spaceship, Inc. on 2026-10-07, and its SSL certificate from Let's Encrypt / YE2 was scanned on 2026-10-09.
The VirusTotal record for voting-theindexfinance.cfd contains a quantitative measurement of scanner detections, reflecting how many security tools flagged the domain at the time of review. MetaMask and SEAL blocklist entries, along with the PhishDestroy internal listing, represent distinct types of security intelligence from different monitoring sources. OTX pulses add further context by capturing community-driven observations within the same timeframe.
For voting-theindexfinance.cfd, retain the VirusTotal and OTX records for future comparison with new security scans. Preserve the MetaMask and SEAL blocklist entries as references for subsequent reviews. Use the PhishDestroy internal listing to inform ongoing technical monitoring of this domain.
Full extracted values, their blockchain and collection source. An address found in page content does not establish who controls it.
0x12f190a9f9d7d37a250758b26824b97ce941bf54Format validated · Domain analysis0x2e0847e8910a9732eb3fb1bb4b70a580adad4fe3Format validated · Domain analysis0x322f0929c4625ed5bad873c95208d54e1c003b2dFormat validated · Domain analysis0x39ADB8acD07427D338b5f1AfAb436A04AbFdB7c4Format validated · Domain analysis0x4a0e65a3eccec6dbe60ae065f2e7bb85fae35eeaFormat validated · Domain analysis0x5f10a1c971b69e47e059e1dc91901b59b3fb49c3Format validated · Domain analysis0x6330d8c3178a418788df01a47479c0ce7ccf450bFormat validated · Domain analysis0x822cc93ffd030293e9842c30bbd678f530701867Format validated · Domain analysis0x86923f96303d656e4aa86d9d42d1e57ad2023fdcFormat validated · Domain analysis0x894e1ec2d74ffe5aef8dc8a9e84686accb964f2aFormat validated · Domain analysis0xaf3d76f1834a1d425780943c99ea8a608f8a93f9Format validated · Domain analysis0xb0992820e760d836549ba69bc7598b4af75dee03Format validated · Domain analysis0xb90a19ff0af67f7779aff50a882a9cff42446400Format validated · Domain analysis0xc0d6457c16cc70d6790dd43521c899c87ce02f35Format validated · Domain analysis0xc72b96e0e48ecd4dc75e1e45396e26300bc39681Format validated · Domain analysis0xd0601ce157db5bdc3162bbac2a2c8af5320d9eecFormat validated · Domain analysis0xd917b029c761d264c6a312bbbcda868658ef86a6Format validated · Domain analysis0xe93237c50d904957cf27e7b1133b510c669c2e74Format validated · Domain analysis0xff080c8ce2e5feadaca0da81314ae59d232d4afdFormat validated · Domain analysisIoC extraction recorded 2026-10-10 04:00:19 UTC
Stored crawler-versus-browser observations for this host, plus a live fingerprint check for Keitaro-style traffic distribution systems.
cloudflareScanner note: alive_content: raw=ok; http=200; via=https_proxy; server=cloudflare
The linked repository preserves daily zone observations across seven ShortDot-operated TLDs, including registration volume and abuse-related indicators. This registry context is supporting background and is not an independent detection for the domain in this report.
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Edge-IP reputation is not attributed to this domain.
lamar.ns.cloudflare.commaria.ns.cloudflare.comLocation describes the IP network.
03691c8119117c90f349d0b50ff94f082575929595a0134e92b887eb6ae0fa1cSaved certificate metadata. Certificate dates without a timezone are shown as stored. Transport encryption does not establish that the site is trustworthy.
Google PageSpeed Insights — mobile performance audit of voting-theindexfinance.cfd · checked Oct 9, 2026
188.114.97.3. 11 recorded events. These records describe collected evidence, outgoing notifications and publication; they do not confirm a complete investigation or a takedown.
We scan suspicious URLs, inspect public results and send evidence through the appropriate abuse-reporting channels. The dated events above show what is recorded for this domain. The directory below explains the wider workflow.
Capture the rendered page, requests and visible infrastructure.
Compare the available engine results and retain the analysis timestamp.
Check whether Google currently lists the URL as unsafe.
Inspect a public scan and its recorded network and classification data.
Look for indicator references and related community intelligence.
Compare archived captures and preserve historical context.
Look for matching indicators and associated threat records.
Inspect certificate records and related hostnames.
Compare security resolver responses and record observed blocking.
Inspect the public DNS, TLS, HTTP and technology surface.
Security services used for scanning, reputation checks and reporting are listed below. A service being listed is not evidence that it received, accepted or acted on this particular domain. Recorded submissions appear in the notification history above.
PD-20261009-68415B Recipient: abuse@spaceship.com AUP & Terms of Service Violations: Acceptable Use Policy: Active phishing operations targeting internet users directly violate standard AUP provisions prohibiting fraud and deceptive practices. Terms of Service: Material breach of service terms regarding malicious use, providing contractual justification for immediate suspension. Applicable Legal Framework (Unknown): International Anti-Cybercrime Regulations Budapest Convention on Cybercrime Universal Fraud Prevention Laws Phishing activities violate international cybercrime conventions and Unknown's domestic fraud laws. Investigation Notice: We fully respect your internal investigation processes and discretion. Prompt remediation protects innocent users while mitigating regulatory compliance scrutiny, legal liability, and brand reputation risks associated with ongoing malicious infrastructure.
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Select your country to get official cybercrime contacts, or create a complaint draft →.
Template-based draft · optional AI wording assistance requires separate consent
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowSubmit suspicious domains to our threat database — protect the community
ReportRecent phishing reports and observed availability changes
MonitorMonitor live threats or contest this listing if you believe it's a false positive