voting-hyperlend.finance
“HyperLend”
voting-hyperlend.finance is a crypto drainer phishing site impersonating HyperLend. Detected by 8/95 VirusTotal vendors, registered via NiceNIC International.
El análisis detallado de PhishDestroy AI se mantiene en inglés para conservar el registro forense original.
Resumen de las pruebas
This domain, voting-hyperlend.finance, operates as a crypto drainer phishing site designed to impersonate the legitimate HyperLend platform. The site targets users by presenting a fraudulent interface that mimics the appearance of a decentralized finance (DeFi) lending service. Once users connect their cryptocurrency wallets, the site executes unauthorized transactions, draining funds from the victim’s account without consent. The threat is classified as a crypto drainer due to its direct financial exploitation mechanism, which bypasses traditional credential theft in favor of immediate asset theft via malicious smart contract interactions. Analysis indicates multiple technical indicators supporting the malicious classification of this domain. The domain was registered on February 21, 2026, through NiceNIC International Group Co., Limited, a registrar frequently associated with high-risk domains. It resolves to the IP address 188.114.97.3 and is flagged by 8 out of 95 security vendors on VirusTotal. Additionally, the domain appears on 4 distinct security blocklists and is actively blocked by wallet security tools such as MetaMask and ScamSniffer. The SSL certificate is issued by Google Trust Services, and the site employs Cloudflare for hosting, which may obscure its true origin and complicate takedown efforts. The Gridinsoft trust score of 0/100 further corroborates its malicious intent. Users who have visited voting-hyperlend.finance or interacted with the site should immediately disconnect any connected wallets and revoke all smart contract approvals associated with the domain. It is critical to audit wallet transactions for unauthorized transfers and report the incident to relevant blockchain security platforms. If funds were transferred, victims should document all transaction hashes and contact their wallet provider for potential recovery options. Additionally, users should monitor their accounts for signs of further compromise and consider resetting credentials for any accounts linked to the wallet. Avoid re-engaging with the domain or any associated URLs to prevent additional exposure.
Inteligencia de seguridad de red Registrar context
Forensic History & Detection Timeline
-
Domain Status Transition Jul 27, 2026 · 00:45 UTCDomain state transitioned from dead to alive.
-
VirusTotal Detections Update Jun 27, 2026 · 00:46 UTCVirusTotal scanner detections updated from 7 to 8. Added scanner alerts: ADMINUSLabs, CRDF, Chong Lua Dao, Forcepoint ThreatSeeker. Resolved alerts: SOCRadar, Seclookup, URLQuery.
-
Cloudflare Radar Scan Mar 7, 2026 · 08:25 UTCCloudflare Radar scan registered: View Radar report.
-
Domain Status Transition Feb 27, 2026 · 07:05 UTCDomain state transitioned from alive to dead.
Proceso de respuesta ante amenazas Pipeline
Estado de la lista de bloqueados pública
Evasion analysis
Cloaking suspected: scanner and victim titles differ
Stored crawler-versus-browser observations for this host, plus a live fingerprint check for Keitaro-style traffic distribution systems.
- Stored cloaking flag
- Not observed
- Puntuación de encubrimiento
- 0/6
- Last cloaking scan
- Server header seen by scanner
cloudflare
Scanner note: cloudflare_ban: raw=cf_phishing_block; http=403; via=https_proxy; server=cloudflare; provider_error=cloudflare_phishing_interstitial
Provider response during scan: cloudflare_phishing_interstitial
Captura guardada · 2 sources
Inteligencia de dominios
Detalles técnicosDNS, SAN de SSL, marcas de tiempo
ICANN OVERSIGHT
Acreditación y contexto RAA
Acreditación y contexto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Latest Classified Outcome 2026-09-21 02:45:59 UTC
Tecnologías · 3 identified
Análisis de VirusTotal
Evidencias archivadas
Análisis del rendimiento del sitio
Google PageSpeed Insights — mobile performance audit of voting-hyperlend.finance · checked Jun 27, 2026
Reportes de la comunidad
Reportado por 1 miembro de la comunidad; visto por primera vez el 12/02/2026
- Reportes almacenados
- 1
- URL únicas reportadas
- 1
Datos y informes externos
¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.