vote-felixcraftai[.]app
vote-felixcraftai.app — Доступно · доступ обмежено (HTTP 403). Тип шахрайства: Crypto Drainer. Зведення доказів: VirusTotal 8/91 (ADMINUSLabs, alphaMountain.ai, Chong Lua Dao, CRDF, CyRadar); Spamhaus DBL_PHISH; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 78/100. Реєстратор: NiceNIC.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
Analysis shows vote-felixcraftai.app was registered on March 03, 2026 and is currently resolving to IP 172.67.145.66, an address associated with a major content‑delivery network located in the United States under ASN 13335. The domain presents a TLS certificate issued by a free certificate authority (Let’s Encrypt) and serves HTTP/3 traffic. Automated scans return an HTTP 403 response and the page title "Just a moment...", a pattern often employed to conceal malicious redirects.
Threat intel indicates the site is classified as a crypto‑drainer, specifically targeting wallet credentials for extraction. Four out of ninety‑five security vendors on a public scanning platform have flagged the domain, and a reputable endpoint‑trust rating assigns it a zero score out of one hundred, confirming a high confidence in its malicious nature. The domain appears on three independent blocklists and is actively blocked by multiple anti‑phishing and cryptocurrency‑wallet protection tools.
Infrastructure observations reveal the use of a CDN service with built‑in browser analytics and HTTP/3 support, which aids in obfuscating the origin server and complicating forensic tracing. The hosting provider's nameservers, listed as adam.ns and danica.ns, are standard for the CDN’s network, further concealing the underlying command‑and‑control infrastructure. No additional infrastructure details beyond the CDN address are observable, leaving the downstream payload delivery mechanisms uncertain.
Defenders should block the domain at perimeter defenses and DNS resolvers, monitor for outbound connections to the associated IP, and enforce strict validation of cryptocurrency transaction requests. Incident response teams should also correlate any wallet access attempts with the observed page title and HTTP 403 response pattern to identify potential compromise. Continuous monitoring of the domain’s reputation scores and blocklist status is recommended, as the active risk level remains high.
Розвіддані з мережевої безпеки Registrar context
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Збережений знімок
Аналітика доменів
Технічні деталіDNS, SAN-адреси SSL, мітки часу
ICANN OVERSIGHT
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Latest Classified Outcome 2026-08-20 02:48:05 UTC
Технології · 3 identified
Performance monitoring tool that measures website speed from real users.
www.cloudflare.comWeb infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Аналіз VirusTotal
Архівні докази
Аналіз продуктивності сайту
Google PageSpeed Insights — mobile performance audit of vote-felixcraftai.app · checked Apr 11, 2026
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога