voting-ethena[.]app
Ringkasan bukti
This domain, voting-ethena.app, is identified as a high-risk generic phishing site targeting users of the Ethena protocol, a synthetic dollar and staking platform. Analysis indicates the domain impersonates Ethena’s governance voting portal, likely to harvest credentials or distribute malicious payloads under the guise of legitimate participation. No specific drainer kit signatures have been confirmed, but the domain’s structure and naming convention strongly suggest intent to deceive users into interacting with fraudulent governance proposals or wallet connections. Infrastructure analysis reveals the domain was registered on June 07, 2026, through NICENIC INTERNATIONAL GROUP CO., LIMITED, a registrar frequently associated with malicious registrations. It currently resolves to the IP address 104.21.39.148, a Cloudflare proxy endpoint, which obscures the true hosting origin. The domain’s SSL certificate is issued by Google Trust Services (WE1), a common practice among threat actors to lend superficial legitimacy. VirusTotal detection shows 6 out of 95 security vendors flag the domain as malicious, while it appears on 3 distinct security blocklists. Notably, the domain is actively blocked by multiple cryptocurrency-focused security tools, including wallet protection and phishing detection systems. As of the latest verification, voting-ethena.app remains active and unresolved, posing an ongoing risk to users. The domain’s use of a future creation date (June 2026) suggests an attempt to evade automated detection systems that rely on domain age as a trust signal. Recommended response actions include immediate blacklisting at the DNS and network levels, as well as user education to verify governance portals through official Ethena channels. Despite mitigation efforts, the domain’s persistence and proxy-based hosting present a residual risk, necessitating continuous monitoring for shifts in infrastructure or payload delivery.
Data Coverage
Intelijen Keamanan Jaringan
Alur Tanggapan Ancaman Pipeline
Cakupan daftar blokir
10 sumber eksternal dipantau · snapshot tersimpan 11/08/2026
8 sumber eksternal dipantau Tidak cocok
Bukti hasil tersimpan
Hasil dan atribusi penonaktifan
- Hasil
protected- Ketersediaan
reachable_protected- Penyebab
cloudflare_challenge- Pelaku
- Cloudflare
- Mekanisme
challenge- Tingkat keyakinan
- 85%
- Pengamatan pertama
- Pengamatan terbaru
SHA-256 bukti a89a0b2b9b69
Linimasa deteksi
-
Cloudflare Radar
Pemindaian Cloudflare Radar tersimpan · Buka pemindaian
-
Ketersediaan
Nilai tersimpan pertama: Tidak diketahui
993d00c35140 -
Ketersediaan
Tidak diketahui → Konten aktif
7f2890fd7b91 -
Ketersediaan
Konten aktif → Dilindungi
6cc53d79b6e7 -
Ketersediaan
Dilindungi → Tidak diketahui
c81d5abb6b1a -
Ketersediaan
Tidak diketahui → Dilindungi
f4b16c2e3345 -
Ketersediaan
Dilindungi → Tidak diketahui
7cebcfd4071c -
Ketersediaan
Tidak diketahui → Dilindungi
b6d599613896 -
Ketersediaan
Dilindungi → Tidak diketahui
ca255b61650a -
Ketersediaan
Tidak diketahui → Dilindungi
e459e59037fa
Tampilkan semua (4)
-
Ketersediaan
Dilindungi → Tidak diketahui
d8f7d37d7f95 -
Ketersediaan
Tidak diketahui → Dilindungi
8a14dd8e0b73 -
Ketersediaan
Dilindungi → Tidak diketahui
afa49a2b04dd -
Ketersediaan
Tidak diketahui → Dilindungi
a89a0b2b9b69
Laporan komunitas
Dilaporkan oleh 1 anggota komunitas; pertama terlihat 07/06/2026
- Laporan tersimpan
- 1
- URL unik yang dilaporkan
- 1
Intelijen Domain
Detail teknisDNS, nama TLS, dan stempel waktu
ICANN OVERSIGHT
Akreditasi dan konteks RAA
Akreditasi dan konteks RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Teknologi
3 teknologi dengan keyakinan tinggi teridentifikasi
Analisis VirusTotal
Apakah Anda Terpengaruh oleh Situs Ini?
Jika Anda memasukkan kredensial akun, informasi pribadi atau pembayaran, atau mengunduh file dari domain ini, segera ambil tindakan. Di bawah ini adalah sumber daya untuk membantu Anda melaporkan insiden tersebut dan melindungi diri Anda sendiri.
Laporkan kepada Pihak Berwenang di Daerah Anda
Pilih negara Anda untuk mendapatkan kontak resmi kejahatan dunia maya, atau membuat draf pengaduan →.
Periksa Domain Apa Pun
Analisis ancaman menggunakan daftar blokir yang disimpan, WHOIS, DNS, dan bukti pemindaian publik
Pindai SekarangLaporkan Phishing
Laporkan domain yang mencurigakan ke basis data ancaman kami — lindungi komunitas
LaporanPemberitahuan Ancaman Real-Time
Laporan phishing terbaru dan perubahan ketersediaan yang diamati
PantauTetap Terinformasi, Tetap Aman
Pantau ancaman secara langsung atau ajukan keberatan terhadap daftar ini jika Anda yakin ini merupakan false positive