votes-tokenworks[.]com
Pemeriksaan phishing dan keamanan votes-tokenworks.com
“TokenWorks™”
votes-tokenworks.com — Konten tidak tersedia (HTTP 500). Jenis penipuan: Credential Phishing. Ringkasan bukti: VT 5/91 (alphaMountain.ai, CRDF, Fortinet, Gridinsoft, SOCRadar); URLScan no malicious verdict; GSB no flag; Spamhaus DBL_PHISH; BL 2 (MetaMask, SEAL); PD 71/100. Registrar: NiceNIC.
Analisis terperinci PhishDestroy AI di bawah tetap berbahasa Inggris untuk menjaga catatan forensik asli.
PhishDestroy first observed votes-tokenworks.com on Jul 25, 2026. Positive findings were recorded by VirusTotal, MetaMask, SEAL, and Spamhaus DBL. Evidence score: 71/100.
VirusTotal recorded 5 detections among 91 engines: alphaMountain.ai, CRDF, Fortinet, Gridinsoft, SOCRadar on Aug 6, 2026 at 02:13 UTC. The external blocklist snapshot contained 2 matches (MetaMask, SEAL) on Aug 7, 2026 at 14:20 UTC. Spamhaus DBL: DBL_PHISH on Jul 25, 2026 at 18:30 UTC. On Jul 25, 2026 at 17:21 UTC, Google Safe Browsing returned no flag; URLScan completed without a malicious verdict (score 0).
HTTP 500 was recorded on Aug 7, 2026 at 02:16 UTC; content was unavailable. Latest classified outcome: unknown; cause origin unreachable; mechanism http 5xx on Aug 7, 2026 at 00:16 UTC. Registration records list NICENIC INTERNATIONAL GROUP CO., LIMITED as the registrar and Jul 25, 2026 as the registration date. At collection time, the domain resolved to 104.21.43.159. Captured page title: “TokenWorks™”. PhishDestroy classified the observed content as Credential Phishing. DOM analysis completed on Jul 25, 2026 at 18:20 UTC; stored DOM score 0/100. IoC extraction completed on Jul 29, 2026 at 02:46 UTC; stored 0 format-validated wallet addresses and 0 Telegram indicators.
Stored full analysis25/07/2026
The domain votes-tokenworks.com was registered on July 25, 2026 through NICENIC INTERNATIONAL GROUP CO., LIMITED. It is currently active and resolves to the IP address 104.21.43.159, which is hosted on Cloudflare infrastructure as indicated by the authoritative nameservers kip.ns.cloudflare.com and meera.ns.cloudflare.com. The domain appears on a single security blocklist, specifically PhishDestroy, confirming that at least one anti‑phishing service has flagged it as malicious.
VirusTotal records show that the domain has been scanned by 91 antivirus and URL‑reputation vendors; none of the scanners have raised a detection, but the absence of a detection does not constitute proof of benign intent. No public information about the site’s SSL certificate, HTTP response codes, page title, or any observed payloads is available, leaving the exact content and tactics employed by the site unverified. The limited visibility means that while the domain is known to be used for credential‑harvesting attempts, the specific phishing kit, targeted brands, or victim demographics have not been identified.
Defenders should treat votes-tokenworks.com as a high‑confidence indicator of compromise (IOC) and block traffic to the domain at the network perimeter and DNS filtering layers. Security teams should also monitor for related domains registered with the same registrar or resolving to the same IP address, and incorporate the domain into threat‑intel feeds used by endpoint detection and response (EDR) solutions. Continuous re‑evaluation is advised, as additional evidence such as page content or malicious payloads may emerge from future sandbox analyses or community reporting.
Intelijen Keamanan Jaringan Registrar Integrity Alert
Alur Tanggapan Ancaman Pipeline
Status Daftar Blokir Publik
Tangkapan tersimpan
Intelijen Domain
Rincian teknisDNS, SAN SSL, cap waktu
ICANN OVERSIGHT
Akreditasi dan konteks RAA
Akreditasi dan konteks RAA
ICANN Sudah Dibayar. Akuntabilitas Tak Kunjung Datang.
Untuk gTLD ini, registrar di atas beroperasi berdasarkan kontrak dengan ICANN. ICANN memungut biaya tahunan, biaya variabel, dan biaya berbasis transaksi yang terkait dengan pendaftaran, perpanjangan, dan transfer.
Akreditasi: dimonetisasi. Akuntabilitas: silakan periksa kembali nanti.
Lalu keajaiban dimulai: ICANN menulis RAA §3.18, registrar menyelidiki penyalahgunaan di dalam basis pelanggannya sendiri, dan para korban menyerahkan bukti secara cuma-cuma sementara setiap lapisan menunggu pihak lain bertindak. Jika itu membuat para korban merasa lebih aman, bagus sekali—ternyata tagihannya bekerja.
Latest Classified Outcome 2026-08-07 02:16:38 UTC
Teknologi · 3 identified
JSDelivr is a free public CDN for open-source projects. It can serve web files directly from the npm registry and GitHub repositories without any configuration.
www.jsdelivr.com Keyakinan 100%Content Delivery Network — caches assets at edge locations for faster global delivery.
bunny.net Keyakinan 100%Analisis VirusTotal
Bukti Terarsip
Analisis Performa Situs
Google PageSpeed Insights — mobile performance audit of votes-tokenworks.com · checked Jul 25, 2026
Bukti & Laporan Eksternal
Apakah Anda Terpengaruh oleh Situs Ini?
Jika Anda memasukkan kredensial akun, informasi pribadi atau pembayaran, atau mengunduh file dari domain ini, segera ambil tindakan. Di bawah ini adalah sumber daya untuk membantu Anda melaporkan insiden tersebut dan melindungi diri Anda sendiri.
Laporkan kepada Pihak Berwenang di Daerah Anda
Pilih negara Anda untuk mendapatkan kontak resmi kejahatan dunia maya, atau membuat draf pengaduan →.
Tentang Laporan Ini: votes-tokenworks.com
Laporan ini menyajikan bukti tersimpan terbaru yang tersedia untuk PhishDestroy. Stempel waktu sumber ditampilkan jika tersedia; ketersediaan dan keputusan vendor dapat berubah setelah pengumpulan.
Situs yang diambil menampilkan judul halaman “TokenWorks™”.
Pada 07/08/2026, votes-tokenworks.com memiliki deteksi dari mesin keamanan 5.
Jika Anda yakin daftar ini tidak akurat, mengajukan banding. Untuk mempelajari metodologi kami, kunjungi halaman pertanyaan umum.
Periksa Domain Apa Pun
Analisis ancaman menggunakan daftar blokir yang disimpan, WHOIS, DNS, dan bukti pemindaian publik
Pindai SekarangLaporkan Phishing
Laporkan domain yang mencurigakan ke basis data ancaman kami — lindungi komunitas
LaporanPemberitahuan Ancaman Real-Time
Laporan phishing terbaru dan perubahan ketersediaan yang diamati
PantauTetap Terinformasi, Tetap Aman
Pantau ancaman secara langsung atau ajukan keberatan terhadap daftar ini jika Anda yakin ini merupakan false positive