vote-felixcraftai[.]app
vote-felixcraftai.app — Accesible · acceso restringido (HTTP 403). Tipo de estafa: Crypto Drainer. Resumen de las pruebas: VirusTotal 8/91 (ADMINUSLabs, alphaMountain.ai, Chong Lua Dao, CRDF, CyRadar); Spamhaus DBL_PHISH; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 78/100. Registrador: NiceNIC.
El análisis detallado de PhishDestroy AI se mantiene en inglés para conservar el registro forense original.
Analysis shows vote-felixcraftai.app was registered on March 03, 2026 and is currently resolving to IP 172.67.145.66, an address associated with a major content‑delivery network located in the United States under ASN 13335. The domain presents a TLS certificate issued by a free certificate authority (Let’s Encrypt) and serves HTTP/3 traffic. Automated scans return an HTTP 403 response and the page title "Just a moment...", a pattern often employed to conceal malicious redirects.
Threat intel indicates the site is classified as a crypto‑drainer, specifically targeting wallet credentials for extraction. Four out of ninety‑five security vendors on a public scanning platform have flagged the domain, and a reputable endpoint‑trust rating assigns it a zero score out of one hundred, confirming a high confidence in its malicious nature. The domain appears on three independent blocklists and is actively blocked by multiple anti‑phishing and cryptocurrency‑wallet protection tools.
Infrastructure observations reveal the use of a CDN service with built‑in browser analytics and HTTP/3 support, which aids in obfuscating the origin server and complicating forensic tracing. The hosting provider's nameservers, listed as adam.ns and danica.ns, are standard for the CDN’s network, further concealing the underlying command‑and‑control infrastructure. No additional infrastructure details beyond the CDN address are observable, leaving the downstream payload delivery mechanisms uncertain.
Defenders should block the domain at perimeter defenses and DNS resolvers, monitor for outbound connections to the associated IP, and enforce strict validation of cryptocurrency transaction requests. Incident response teams should also correlate any wallet access attempts with the observed page title and HTTP 403 response pattern to identify potential compromise. Continuous monitoring of the domain’s reputation scores and blocklist status is recommended, as the active risk level remains high.
Inteligencia de seguridad de red Registrar context
Proceso de respuesta ante amenazas Pipeline
Estado de la lista de bloqueados pública
Captura guardada
Inteligencia de dominios
Detalles técnicosDNS, SAN de SSL, marcas de tiempo
ICANN OVERSIGHT
Acreditación y contexto RAA
Acreditación y contexto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Latest Classified Outcome 2026-08-20 02:48:05 UTC
Tecnologías · 3 identified
Performance monitoring tool that measures website speed from real users.
www.cloudflare.comWeb infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Análisis de VirusTotal
Evidencias archivadas
Análisis del rendimiento del sitio
Google PageSpeed Insights — mobile performance audit of vote-felixcraftai.app · checked Apr 11, 2026
Datos y informes externos
¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.