votes-ethereal[.]xyz
“Pieni hetki...”
votes-ethereal.xyz — Ошибка сервера (HTTP 502). Тип мошенничества: Crypto Scam. Сводка доказательств: VirusTotal 3/95 (CRDF, Gridinsoft, Trustwave); PhishDestroy score 65/100. Регистратор: NiceNIC.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
votes-ethereal.xyz is currently listed as offline but remains of interest to defenders because it has been identified as a crypto‑related phishing site. The domain was registered on 28 September 2025 through NiceNIC International Group Co., Limited and is hosted on Cloudflare’s network (ASN 13335) with the IP address 104.21.2.207 located in the United States. Authoritative name servers kianchau.ns.cloudflare.com and meilani.ns.cloudflare.com resolve the domain, confirming the use of Cloudflare’s DNS infrastructure. No TLS certificate is presented, indicating that the site was served over plain HTTP when it was reachable.
The page title returned from the last known capture is “Pieni hetki…”, which offers no direct indication of the targeted brand or service. Gridinsoft assigned a trust score of 0 out of 100, and the domain appears on at least one public security blocklist. VirusTotal reports three positive detections out of ninety‑five scanners, reinforcing the suspicion of malicious intent. PhishDestroy has also added the domain to its blocklist, and the overall classification in the intelligence feed is “Crypto Scam”.
The combination of recent creation, low trust rating, lack of encryption, and multiple independent detections suggests an active phishing campaign aimed at luring victims into cryptocurrency‑related fraud. Defenders should continue to block the domain at perimeter firewalls and DNS filtering solutions, monitor for any resurgence of the IP address or associated Cloudflare‑hosted assets, and consider adding the domain to internal threat‑intel feeds. Because the site is offline, a live forensic capture is not possible; however, historical snapshots, if available, should be examined for payloads or command‑and‑control indicators. Ongoing vigilance is advised, especially for users who may receive unsolicited messages referencing cryptocurrency transactions that could redirect to this domain.
Данные сетевой безопасности Registrar context
Процесс реагирования на угрозы
Статус в публичных блок-листах
Сохранённый снимок
Аналитика доменов
Технические сведенияDNS, SAN в протоколе SSL, временные метки
ICANN OVERSIGHT
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Latest Classified Outcome 2026-08-19 03:31:41 UTC
Анализ VirusTotal
Доказательства и внешние отчеты
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание