vote-navis[.]pages[.]dev
“NAVI”
Resumo das evidências
PhishDestroy identifies vote-navis.pages.dev as a high-risk crypto wallet drainer posing under the guise of a legitimate service. This domain was flagged due to its active role in cryptocurrency theft, specifically designed to deceive users into connecting their wallets under false pretenses. Upon connection, the drainer silently siphons funds from unsuspecting victims, often mimicking popular crypto platforms or tools to gain trust. The domain operates under Cloudflare's infrastructure, leveraging their CDN and security features to obscure its true origin while maintaining accessibility. Such drainers are notorious for their low initial detection rates, relying on the delay between discovery and flagging by security services to maximize their victim pool. This domain exhibits several technical red flags that warrant immediate caution. Registered through Cloudflare, Inc., vote-navis.pages.dev resolves to the IP address 188.114.97.3 and is secured with a Google Trust Services SSL certificate, which lends it a veneer of legitimacy. However, VirusTotal currently reports 1 out of 95 antivirus engines detecting it as malicious, a common characteristic of newly deployed or stealthily operating drainers. Cloudflare's infrastructure further complicates tracking, as it masks the domain's true hosting location and ownership details. The absence of detections does not equate to safety; instead, it highlights the domain's effectiveness in evading early-stage detection mechanisms, emphasizing the need for proactive verification tools like PhishDestroy. Users who have interacted with vote-navis.pages.dev should act swiftly to mitigate potential losses. First, disconnect any connected cryptocurrency wallets or revoke any permissions granted to untrusted domains through tools like WalletConnect or your wallet's built-in dApp browser settings. Next, transfer remaining funds to a new, secure wallet to prevent further unauthorized access. Finally, scan your device for malware or malicious browser extensions that may have been installed during the interaction, as drainers often bundle additional payloads. PhishDestroy strongly advises against entering any credentials or connecting wallets to domains that have not been independently verified. Report this domain immediately to PhishDestroy and relevant crypto communities to aid in its deactivation and to warn others. Remaining vigilant and verifying URLs before interaction is the most effective defense against such crypto drainers.
Data Coverage
Inteligência de segurança de rede
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Nextron YARA rules | vote-navis.pages.dev/assets/secure.php?req=ping |
malware | PHP webshell obfuscated by encoding of mixed hex and dec |
| Nextron YARA rules | vote-navis.pages.dev/assets/secure.php?req=ping |
malware | Known PHP Webshells which contain unique strings, lousy rule for low hanging fruits. Most are catched by other rules in here but maybe these catch different ver |
Pipeline de resposta a ameaças
Cobertura de listas de bloqueio
10 fontes externas monitoradas · instantâneo de 13/08/2026
7 fontes externas monitoradas Sem correspondência
Tecnologias
4 tecnologias identificadas com alta confiança
Análise do VirusTotal
Análise de desempenho do site
Google PageSpeed Insights — mobile performance audit of vote-navis.pages.dev · checked May 11, 2026
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo