vote-aerodrome[.]live
vote-aerodrome.live — Контент недоступний (HTTP 502). Тип шахрайства: Generic Phishing. Зведення доказів: VirusTotal 4/91 (alphaMountain.ai, CRDF, Gridinsoft, SOCRadar); URLQuery 2 alerts; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 83/100. Реєстратор: PDR.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
PhishDestroy identifies vote-aerodrome.live as a confirmed phishing domain hosting a fake voting portal, likely targeting cryptocurrency or token holders by impersonating Aerodrome Finance. This domain masquerades as a legitimate platform to harvest login credentials and sensitive financial data under the guise of governance participation. The threat is active and operational, with no current detections on VirusTotal despite clear malicious intent. The domain vote-aerodrome.live was registered on June 16, 2026, through PDR Ltd. d/b/a PublicDomainRegistry.com. It resolves to IP address 188.114.97.3 and currently shows 2 out of 95 VirusTotal detections. While not yet blacklisted, this domain remains untrusted with no positive reputation indicators. The recent registration date combined with the spoofed branding (Aerodrome Finance) indicates a likely opportunistic attack targeting crypto communities during periods of high governance activity. This threat type—brand impersonation phishing—employs urgency and false legitimacy to trick users into entering wallet addresses or credentials. Indicators include the domain name (containing 'aerodrome'), suspicious IP reputation (188.114.97.3 associated with multiple low-trust domains), and zero detections on leading scanners. Users must avoid accessing this domain, verify URLs via official sources, enable wallet or platform alerts for unusual transactions, and report suspicious links to their crypto wallet or exchange. Platforms should consider proactive takedown requests given the low VT score and high risk of credential theft.
Розвіддані з мережевої безпеки
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Hagezi Threat Feed | vote-aerodrome.live |
malicious | Sinkholed |
| DNS4EU | vote-aerodrome.live |
malicious | Sinkholed |
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Збережений знімок
Аналітика доменів
Технічні деталіDNS, SAN-адреси SSL, мітки часу
ICANN OVERSIGHT
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Аналіз VirusTotal
Докази та зовнішні звіти
PD-20260624-9280E0 Recipient: abuse@publicdomainregistry.com Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога