votes-ethereal[.]xyz
“Pieni hetki...”
votes-ethereal.xyz — Помилка сервера (HTTP 502). Тип шахрайства: Crypto Scam. Зведення доказів: VirusTotal 3/95 (CRDF, Gridinsoft, Trustwave); PhishDestroy score 65/100. Реєстратор: NiceNIC.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
votes-ethereal.xyz is currently listed as offline but remains of interest to defenders because it has been identified as a crypto‑related phishing site. The domain was registered on 28 September 2025 through NiceNIC International Group Co., Limited and is hosted on Cloudflare’s network (ASN 13335) with the IP address 104.21.2.207 located in the United States. Authoritative name servers kianchau.ns.cloudflare.com and meilani.ns.cloudflare.com resolve the domain, confirming the use of Cloudflare’s DNS infrastructure. No TLS certificate is presented, indicating that the site was served over plain HTTP when it was reachable.
The page title returned from the last known capture is “Pieni hetki…”, which offers no direct indication of the targeted brand or service. Gridinsoft assigned a trust score of 0 out of 100, and the domain appears on at least one public security blocklist. VirusTotal reports three positive detections out of ninety‑five scanners, reinforcing the suspicion of malicious intent. PhishDestroy has also added the domain to its blocklist, and the overall classification in the intelligence feed is “Crypto Scam”.
The combination of recent creation, low trust rating, lack of encryption, and multiple independent detections suggests an active phishing campaign aimed at luring victims into cryptocurrency‑related fraud. Defenders should continue to block the domain at perimeter firewalls and DNS filtering solutions, monitor for any resurgence of the IP address or associated Cloudflare‑hosted assets, and consider adding the domain to internal threat‑intel feeds. Because the site is offline, a live forensic capture is not possible; however, historical snapshots, if available, should be examined for payloads or command‑and‑control indicators. Ongoing vigilance is advised, especially for users who may receive unsolicited messages referencing cryptocurrency transactions that could redirect to this domain.
Розвіддані з мережевої безпеки Registrar context
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Збережений знімок
Аналітика доменів
Технічні деталіDNS, SAN-адреси SSL, мітки часу
ICANN OVERSIGHT
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Latest Classified Outcome 2026-08-19 03:31:41 UTC
Аналіз VirusTotal
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога