vote-perleslabs[.]pages[.]dev
“Earn Rewards for Training AI with Expert Data | Perle Labs”
Ringkasan bukti
PhishDestroy identifies vote-perleslabs.pages.dev as an active crypto drainer posing as a Perles Labs site. The domain leverages a Pages.dev front-end to spoof a legitimate-looking page that prompts wallet connections. Once connected, hidden scripts extract private keys and seed phrases, draining cryptocurrency holdings to attacker-controlled wallets. This model mirrors recent high-profile campaigns targeting DeFi users. Security researchers note the domain’s immediate redirection from phishing links to obfuscated drainer scripts hosted on Cloudflare’s edge network, indicating a deliberately engineered deception pipeline designed for rapid fund exfiltration.
This domain was flagged by PhishDestroy with a risk status of 'active' and a generic phishing type. The threat intelligence shows SSL certification issued by Google Trust Services, though this alone does not validate authenticity. VirusTotal currently reports 0 out of 95 detection engines flagging the domain, suggesting low static signature coverage despite behavioral indicators. The domain is registered through Cloudflare, Inc., resolving to IP 172.66.47.73 and appears on 1 known security blocklist. Blocking by MetaMask further supports suspicions of malicious intent, as the browser extension has flagged the domain for hosting wallet-draining code.
Users who visited vote-perleslabs.pages.dev should immediately disconnect any connected wallets, revoke any unauthorized approvals, and transfer remaining funds to a new, secure wallet. Scan device for malware using reputable antivirus software and clear browser cache and cookies. Report the domain to PhishDestroy and your wallet provider. Avoid reusing seed phrases and ensure 2FA is enabled on all accounts. Exercise extreme caution with any unsolicited links or unexpected wallet connection prompts to prevent further compromise.
Data Coverage
Intelijen Keamanan Jaringan
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Nextron YARA rules | vote-perleslabs.pages.dev/assets/secure.php?req=ping |
malware | PHP webshell obfuscated by encoding of mixed hex and dec |
| Nextron YARA rules | vote-perleslabs.pages.dev/assets/secure.php?req=ping |
malware | Known PHP Webshells which contain unique strings, lousy rule for low hanging fruits. Most are catched by other rules in here but maybe these catch different ver |
Alur Tanggapan Ancaman Pipeline
Cakupan daftar blokir
10 sumber eksternal dipantau · snapshot tersimpan 12/08/2026
8 sumber eksternal dipantau Tidak cocok
Analisis VirusTotal
Analisis Performa Situs
Google PageSpeed Insights — mobile performance audit of vote-perleslabs.pages.dev · checked May 14, 2026
Apakah Anda Terpengaruh oleh Situs Ini?
Jika Anda memasukkan kredensial akun, informasi pribadi atau pembayaran, atau mengunduh file dari domain ini, segera ambil tindakan. Di bawah ini adalah sumber daya untuk membantu Anda melaporkan insiden tersebut dan melindungi diri Anda sendiri.
Laporkan kepada Pihak Berwenang di Daerah Anda
Pilih negara Anda untuk mendapatkan kontak resmi kejahatan dunia maya, atau membuat draf pengaduan →.
Periksa Domain Apa Pun
Analisis ancaman menggunakan daftar blokir yang disimpan, WHOIS, DNS, dan bukti pemindaian publik
Pindai SekarangLaporkan Phishing
Laporkan domain yang mencurigakan ke basis data ancaman kami — lindungi komunitas
LaporanPemberitahuan Ancaman Real-Time
Laporan phishing terbaru dan perubahan ketersediaan yang diamati
PantauTetap Terinformasi, Tetap Aman
Pantau ancaman secara langsung atau ajukan keberatan terhadap daftar ini jika Anda yakin ini merupakan false positive