MALICIOUS — CRITICAL
votes-asterdex[.]one
PhishDestroy identifies votes-asterdex.one as an active phishing domain designed to impersonate Asterdex voting services, posing an elevated threat to users seeking legitimate platforms.
- VirusTotal
- 6 detections
- Blocklists
- 2 · MetaMask, SEAL
- Ketersediaan
- Konten tidak tersedia · HTTP 502
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
votes-asterdex.one — Konten tidak tersedia (HTTP 502). Jenis penipuan: Fake Airdrop. Ringkasan bukti: VirusTotal 6 detections (engine total unavailable) (ADMINUSLabs, alphaMountain.ai, Emsisoft, Fortinet, Netcraft); URLQuery 4 alerts; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 76/100. Registrar: PDR.
Analisis terperinci PhishDestroy AI di bawah tetap berbahasa Inggris untuk menjaga catatan forensik asli.
Evidence Analysis
PhishDestroy identifies votes-asterdex.one as an active phishing domain designed to impersonate Asterdex voting services, posing an elevated threat to users seeking legitimate platforms. This domain mimics official voting interfaces to deceive visitors into surrendering sensitive credentials or financial details under false pretenses. votes-asterdex.one was registered through PDR Ltd. via PublicDomainRegistry.com on May 4, 2026, and is flagged by 6 of 95 VirusTotal security vendors as malicious. The domain resolves to IP address 188.114.96.3, where it may host fraudulent content or redirect victims to further scam pages. Despite using a seemingly legitimate SSL certificate from Let's Encrypt, the combination of recent registration, low detection rate among vendors, and suspicious hosting infrastructure strongly indicates malicious intent. Users who visited votes-asterdex.one should immediately scan their devices for malware or unauthorized access, avoid entering any personal or financial information, and check bank statements for suspicious transactions. Disable browser autofill for saved credentials and consider resetting passwords used on this site. Report the domain to your antivirus provider and local cybercrime units to help prevent others from becoming victims.
Cakupan data12 recorded checks
Intelijen Keamanan Jaringan
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DigiCert UltraDNS | claudjaframework.beer |
malicious | Sinkholed |
| DNS4EU | claudjaframework.beer |
malicious | Sinkholed |
| Hagezi Threat Feed | claudjaframework.beer |
malicious | Sinkholed |
| Quad9 DNS | claudjaframework.beer |
malicious | Sinkholed |
Alur Tanggapan Ancaman Pipeline
Status Daftar Blokir Publik
Tangkapan tersimpan
Intelijen Domain
Rincian teknisDNS, SAN SSL, cap waktu
ICANN OVERSIGHT
Akreditasi dan konteks RAA
Akreditasi dan konteks RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Analisis VirusTotal
Bukti & Laporan EksternalIndependent lookups and source reports
PD-20260506-EF5502 Recipient: abuse@publicdomainregistry.com Victim safety and official reportingImmediate actions and verified reporting channels
Jika Anda memasukkan kredensial akun, informasi pribadi atau pembayaran, atau mengunduh file dari domain ini, segera ambil tindakan. Di bawah ini adalah sumber daya untuk membantu Anda melaporkan insiden tersebut dan melindungi diri Anda sendiri.
Laporkan kepada Pihak Berwenang di Daerah Anda
Pilih negara Anda untuk mendapatkan kontak resmi kejahatan dunia maya, atau membuat draf pengaduan →.