voting-linea[.]xyz
“Linea Rewards Update”
voting-linea.xyz — Контент недоступен (HTTP 502). Олицетворение бренда: Google; Тип мошенничества: Tech Support Scam. Сводка доказательств: VirusTotal 14/93 (ChainPatrol, alphaMountain.ai, BitDefender, CRDF, CyRadar); URLScan malicious verdict; Spamhaus DBL_PHISH; 1 external blocklist match (ScamSniffer); PhishDestroy score 92/100.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
Analysis of voting-linea.xyz shows that the domain was registered on 21 February 2026 and is currently offline. The site presented a page titled “Linea Rewards Update” and claimed to impersonate Google, consistent with the reported tech‑support scam classification. The domain resolves to 104.21.9.74, an address owned by Cloudflare, Inc. (AS13335) located in the United States. TLS inspection reveals a certificate identified as “WE1”, indicating the use of a generic or possibly compromised certificate rather than a Google‑issued chain.
VirusTotal scans returned 14 positive detections out of 93 participating scanners, confirming that multiple security vendors consider the site malicious. Independent blocklist feeds have added the domain to two separate blocklists, and it is actively listed by PhishDestroy and ScamSniffer, reinforcing the malicious reputation. No Safe Browsing or Open Threat Exchange entries are referenced in the available data, leaving those sources unverified for this indicator.
Because the site is already taken offline, immediate mitigation focuses on preventing future resolution attempts; defenders should add the domain and its IP address to local deny lists, enforce DNS‑level blocking, and monitor for any re‑registration attempts. Continued observation of Cloudflare‑associated IP ranges for similar patterns is recommended, as the infrastructure is commonly reused by threat actors. At present, the only concrete evidence consists of the page title, registration date, hosting details, SSL certificate label, vendor detection count, and blocklist listings; any additional behavioural characteristics of the payload or victim interaction remain unknown pending further investigation.
Процесс реагирования на угрозы
Статус в публичных блок-листах
Анализ VirusTotal
Доказательства и внешние отчеты
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание