MALICIOUS — CRITICAL
vote-8zf[.]pages[.]dev
Analysis of vote-8zf.pages.dev shows a newly registered site (May 11 2026) hosted on Cloudflare Pages and serving content over HTTPS with a Google Trust Services certificate.
- VirusTotal
- 3/91
- Blocklists
- 3 · MetaMask, ScamSniffer
- 가용성
- 마지막으로 알려진 활성 · HTTP 200
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
vote-8zf.pages.dev — 마지막으로 알려진 활성 (HTTP 200). 사기 유형: Crypto Drainer. 증거 요약: VirusTotal 3/91 (alphaMountain.ai, Gridinsoft, LevelBlue); 3 external blocklist matches (MetaMask, ScamSniffer, SEAL); PhishDestroy score 84/100. 등록기관: Cloudflare Pages.
원본 포렌식 기록을 보존하기 위해 아래의 상세 PhishDestroy AI 분석은 영어로 유지됩니다.
Evidence Analysis
Analysis of vote-8zf.pages.dev shows a newly registered site (May 11 2026) hosted on Cloudflare Pages and serving content over HTTPS with a Google Trust Services certificate. The page title advertises “Save, Grow, Spend. Do more with your crypto | ether.fi”, matching a crypto‑drainer campaign that attempts to lure cryptocurrency users into authorizing transfers. The domain resolves to IP 188.114.97.3, an address owned by Cloudflare, Inc. in Canada. Infrastructure indicators include a Gridinsoft trust score of 0/100 and inclusion on four external blocklists. Multiple anti‑phishing feeds (PhishDestroy, MetaMask, SEAL, ScamSniffer) have already flagged the host as malicious, and the site returns HTTP 200, confirming active content delivery. Defenders should treat vote‑8zf.pages.dev as a high‑risk indicator. Network monitoring should block outbound connections to the resolved IP and any future DNS resolutions of the domain. Email gateways and web proxies ought to enforce deny‑list rules for the domain and its parent zone (pages.dev). Because the site leverages a legitimate SSL certificate, TLS inspection may be required to detect the malicious payload. Continuous watch for new sub‑domains under pages.dev is advisable, given the ease of generating additional clones on the same hosting platform. At present, no further technical artifacts such as payload hashes or command‑and‑control endpoints have been disclosed, so threat‑intel teams should prioritize collection of request/response logs should the domain be accessed.
데이터 적용 범위12 recorded checks
위협 대응 Pipeline
공개 차단 목록 상태
도메인 인텔리전스
기술적 세부 사항DNS, SSL SAN, 타임스탬프
VirusTotal 분석
증거 및 외부 보고서Independent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
계정 자격 증명, 개인 정보 또는 결제 정보를 입력했거나 이 도메인에서 파일을 다운로드한 경우 즉시 조치를 취하세요. 다음은 사건을 신고하고 자신을 보호하는 데 도움이 되는 리소스입니다.
지역 당국에 신고하십시오
공식 사이버 범죄 연락처 또는 불만사항 초안 작성 →를 받으려면 국가를 선택하세요.