voting-linea[.]xyz
“Linea Rewards Update”
voting-linea.xyz — Conteúdo indisponível (HTTP 502). Representação da marca: Google; Tipo de golpe: Tech Support Scam. Resumo das evidências: VirusTotal 14/93 (ChainPatrol, alphaMountain.ai, BitDefender, CRDF, CyRadar); URLScan malicious verdict; Spamhaus DBL_PHISH; 1 external blocklist match (ScamSniffer); PhishDestroy score 92/100.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
Analysis of voting-linea.xyz shows that the domain was registered on 21 February 2026 and is currently offline. The site presented a page titled “Linea Rewards Update” and claimed to impersonate Google, consistent with the reported tech‑support scam classification. The domain resolves to 104.21.9.74, an address owned by Cloudflare, Inc. (AS13335) located in the United States. TLS inspection reveals a certificate identified as “WE1”, indicating the use of a generic or possibly compromised certificate rather than a Google‑issued chain.
VirusTotal scans returned 14 positive detections out of 93 participating scanners, confirming that multiple security vendors consider the site malicious. Independent blocklist feeds have added the domain to two separate blocklists, and it is actively listed by PhishDestroy and ScamSniffer, reinforcing the malicious reputation. No Safe Browsing or Open Threat Exchange entries are referenced in the available data, leaving those sources unverified for this indicator.
Because the site is already taken offline, immediate mitigation focuses on preventing future resolution attempts; defenders should add the domain and its IP address to local deny lists, enforce DNS‑level blocking, and monitor for any re‑registration attempts. Continued observation of Cloudflare‑associated IP ranges for similar patterns is recommended, as the infrastructure is commonly reused by threat actors. At present, the only concrete evidence consists of the page title, registration date, hosting details, SSL certificate label, vendor detection count, and blocklist listings; any additional behavioural characteristics of the payload or victim interaction remain unknown pending further investigation.
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Análise do VirusTotal
Evidências e relatórios externos
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo