MALICIOUS — HIGH
byvotes[.]space
3 security engines flagged the domain; 2 public blocklists listed it (MetaMask, SEAL); the latest stored check returned HTTP 502.
- VirusTotal
- 3 detections
- Blocklists
- 2 · MetaMask, SEAL
- Disponibilità
- Contenuto non disponibile · HTTP 502
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
byvotes.space — Contenuto non disponibile (HTTP 502). Tipo di truffa: Crypto Drainer. Riepilogo delle prove: VirusTotal 3 detections (engine total unavailable) (Ermes, Gridinsoft, SOCRadar); 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 66/100. Registrar: Hostinger.
L’analisi dettagliata di PhishDestroy AI resta in inglese per preservare il rapporto forense originale.
Evidence Digest
byvotes.space is classified high with an evidence score of 66/100. 3 security engines flagged the domain; 2 public blocklists listed it (MetaMask, SEAL). Registered 3 May 2026 via HOSTINGER operations, UAB, hosted on 188.114.97.3 (Cloudflare, Inc., CA). The latest stored check on 9 Aug 2026 returned HTTP 502 and includes a capture. 1 outgoing abuse report is recorded, most recently on 4 May 2026.
Stored generated summary (templated)mistral · 26/06/2026
Retained for the record. This text repeats stored detection facts and is not presented as authored analysis.
This domain, byvotes.space, is identified as a crypto drainer phishing site designed to impersonate legitimate voting or polling platforms to deceive users into connecting cryptocurrency wallets. Once connected, the site executes unauthorized transactions, draining digital assets from victims' wallets without consent. The threat specifically targets users through social engineering tactics, leveraging fake voting incentives or rewards to lower suspicion and prompt wallet connections. Analysis indicates the site employs obfuscated JavaScript to interact with wallet APIs, a common technique in crypto drainer schemes to bypass basic security checks. Infrastructure analysis reveals concrete indicators of malicious activity. The domain was registered on May 03, 2026, through HOSTINGER operations, UAB, a registrar frequently associated with phishing campaigns. It resolves to the IP address 188.114.97.3 and is currently offline, though this does not mitigate prior exposure risks. Security vendors on VirusTotal flagged the domain at a rate of 3/95, while it appears on three independent security blocklists, including high-confidence threat intelligence feeds. Technologies detected include Node.js, Vue.js, and Nuxt.js, which are often used to create dynamic, interactive phishing interfaces. Additionally, the use of Cloudflare and HTTP/3 suggests an attempt to mask infrastructure and evade detection through encrypted traffic. Users who visited byvotes.space or interacted with its content should take immediate remedial actions. First, disconnect any cryptocurrency wallets that were linked to the site and revoke all active session permissions via wallet management interfaces. Monitor transaction histories for unauthorized activity and report suspicious transactions to the respective blockchain network or wallet provider. If credentials or private keys were entered, assume they are compromised and migrate assets to a new wallet with a fresh seed phrase. Scan local devices for malware using updated security tools, as phishing sites may deploy secondary payloads. Finally, report the domain to relevant security communities to aid in broader threat mitigation efforts.
Copertura dei dati12 recorded checks
Informazioni sulla sicurezza di rete
Pipeline di risposta alle minacce
Stato della lista di blocco pubblica
Acquisizione salvata
Analisi dei domini
Dettagli tecniciDNS, SAN SSL, timestamp
ICANN OVERSIGHT
Accreditamento e contesto RAA
Accreditamento e contesto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Tecnologie · 6 identified
Node.js is an open-source, cross-platform, JavaScript runtime environment that executes JavaScript code outside a web browser.
nodejs.org Confidenza al 100%Vue.js is an open-source model–view–viewmodel JavaScript framework for building user interfaces and single-page applications.
vuejs.org Confidenza al 100%Cloudflare Browser Insights is a tool that measures the performance of websites from the perspective of users.
www.cloudflare.com Confidenza al 100%Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com Confidenza al 100%HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org Confidenza al 100%Analisi di VirusTotal
Analisi delle prestazioni del sito
Google PageSpeed Insights — mobile performance audit of byvotes.space · checked Jun 26, 2026
Dati e relazioni esterneIndependent lookups and source reports
PD-20260504-2E147F Recipient: abuse@hostinger.com Victim safety and official reportingImmediate actions and verified reporting channels
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.