vote-perleslabs[.]pages[.]dev
“Earn Rewards for Training AI with Expert Data | Perle Labs”
Riepilogo delle prove
PhishDestroy identifies vote-perleslabs.pages.dev as an active crypto drainer posing as a Perles Labs site. The domain leverages a Pages.dev front-end to spoof a legitimate-looking page that prompts wallet connections. Once connected, hidden scripts extract private keys and seed phrases, draining cryptocurrency holdings to attacker-controlled wallets. This model mirrors recent high-profile campaigns targeting DeFi users. Security researchers note the domain’s immediate redirection from phishing links to obfuscated drainer scripts hosted on Cloudflare’s edge network, indicating a deliberately engineered deception pipeline designed for rapid fund exfiltration.
This domain was flagged by PhishDestroy with a risk status of 'active' and a generic phishing type. The threat intelligence shows SSL certification issued by Google Trust Services, though this alone does not validate authenticity. VirusTotal currently reports 0 out of 95 detection engines flagging the domain, suggesting low static signature coverage despite behavioral indicators. The domain is registered through Cloudflare, Inc., resolving to IP 172.66.47.73 and appears on 1 known security blocklist. Blocking by MetaMask further supports suspicions of malicious intent, as the browser extension has flagged the domain for hosting wallet-draining code.
Users who visited vote-perleslabs.pages.dev should immediately disconnect any connected wallets, revoke any unauthorized approvals, and transfer remaining funds to a new, secure wallet. Scan device for malware using reputable antivirus software and clear browser cache and cookies. Report the domain to PhishDestroy and your wallet provider. Avoid reusing seed phrases and ensure 2FA is enabled on all accounts. Exercise extreme caution with any unsolicited links or unexpected wallet connection prompts to prevent further compromise.
Data Coverage
Informazioni sulla sicurezza di rete
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Nextron YARA rules | vote-perleslabs.pages.dev/assets/secure.php?req=ping |
malware | PHP webshell obfuscated by encoding of mixed hex and dec |
| Nextron YARA rules | vote-perleslabs.pages.dev/assets/secure.php?req=ping |
malware | Known PHP Webshells which contain unique strings, lousy rule for low hanging fruits. Most are catched by other rules in here but maybe these catch different ver |
Pipeline di risposta alle minacce
Copertura delle blocklist
10 fonti esterne monitorate · snapshot del 11/08/2026
8 fonti esterne monitorate Nessuna corrispondenza
Analisi di VirusTotal
Analisi delle prestazioni del sito
Google PageSpeed Insights — mobile performance audit of vote-perleslabs.pages.dev · checked May 14, 2026
Questo sito ti ha influenzato in qualche modo?
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.
Verifica qualsiasi dominio
Analisi delle minacce utilizzando blocklist archiviate, WHOIS, DNS e prove di scansione pubblica
Scansiona oraSegnala un tentativo di phishing
Segnala i domini sospetti al nostro database delle minacce — proteggi la comunità
SegnalaFeed in tempo reale sulle minacce
Segnalazioni recenti di phishing e modifiche osservate della disponibilità
MonitoraRimani informato, rimani al sicuro
Controlla le minacce in tempo reale oppure contesta questa segnalazione se ritieni che si tratti di un falso positivo