MALICIOUS — CRITICAL
vote-firelight[.]fi
1 of 91 security engines flagged the domain; 2 public blocklists listed it (MetaMask, SEAL); the latest stored check returned HTTP 403.
- VirusTotal
- 1/91
- Blocklists
- 2 · MetaMask, SEAL
- Disponibilità
- Raggiungibile · accesso limitato · HTTP 403
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
vote-firelight.fi — Raggiungibile · accesso limitato (HTTP 403). Riepilogo delle prove: VirusTotal 1/91 (Gridinsoft); 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 83/100.
L’analisi dettagliata di PhishDestroy AI resta in inglese per preservare il rapporto forense originale.
Evidence Digest
vote-firelight.fi is classified critical with an evidence score of 83/100. 1 of 91 security engines flagged the domain; 2 public blocklists listed it (MetaMask, SEAL). Registered 6 May 2026, hosted on 188.114.97.3 (Cloudflare, Inc., CA). The latest stored check on 9 Aug 2026 returned HTTP 403.
Stored generated summary (templated)mistral · 12/07/2026
Retained for the record. This text repeats stored detection facts and is not presented as authored analysis.
This domain, vote-firelight.fi, is actively flagged as a high-risk phishing resource by multiple threat intelligence sources as of July 12, 2026. Analysis indicates the domain was registered on May 6, 2026, and currently resolves to the IP address 188.114.97.3, which is associated with Cloudflare infrastructure in Canada. The domain is blocked by at least three security blocklists, including PhishDestroy, MetaMask, and SEAL, and has been identified in one AlienVault OTX threat intelligence pulse. A Gridinsoft trust score of 0 out of 100 further corroborates its malicious classification, though only one of 95 security vendors on VirusTotal currently flags it as malicious. Infrastructure examination reveals the site is still operational, returning an HTTP 403 status code, which suggests access restrictions are in place but does not confirm takedown. The SSL certificate is issued by Let's Encrypt, a common choice for both legitimate and malicious domains, and does not inherently indicate compromise. The domain's naming convention, combining 'vote' with a seemingly random term, aligns with patterns observed in credential-harvesting campaigns targeting users through fake login portals or survey scams. Defenders should treat this domain as an active threat. While the exact phishing kit or targeted brand remains unconfirmed, the domain's presence on multiple blocklists and its recent registration support its classification as malicious. Network-level blocking is recommended for all endpoints, and security teams should monitor for connections to 188.114.97.3 or related subdomains. Given the domain's use of Cloudflare, additional scrutiny of other domains sharing the same IP or ASN may uncover related malicious activity. No evidence currently suggests this domain is part of a broader campaign, but further investigation is warranted if internal logs show attempted access.
Copertura dei dati12 recorded checks
Pipeline di risposta alle minacce
Stato della lista di blocco pubblica
Analisi dei domini
Dettagli tecniciDNS, SAN SSL, timestamp
Analisi di VirusTotal
Dati e relazioni esterneIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.