voting-ethena[.]app
Зведення доказів
This domain, voting-ethena.app, is identified as a high-risk generic phishing site targeting users of the Ethena protocol, a synthetic dollar and staking platform. Analysis indicates the domain impersonates Ethena’s governance voting portal, likely to harvest credentials or distribute malicious payloads under the guise of legitimate participation. No specific drainer kit signatures have been confirmed, but the domain’s structure and naming convention strongly suggest intent to deceive users into interacting with fraudulent governance proposals or wallet connections. Infrastructure analysis reveals the domain was registered on June 07, 2026, through NICENIC INTERNATIONAL GROUP CO., LIMITED, a registrar frequently associated with malicious registrations. It currently resolves to the IP address 104.21.39.148, a Cloudflare proxy endpoint, which obscures the true hosting origin. The domain’s SSL certificate is issued by Google Trust Services (WE1), a common practice among threat actors to lend superficial legitimacy. VirusTotal detection shows 6 out of 95 security vendors flag the domain as malicious, while it appears on 3 distinct security blocklists. Notably, the domain is actively blocked by multiple cryptocurrency-focused security tools, including wallet protection and phishing detection systems. As of the latest verification, voting-ethena.app remains active and unresolved, posing an ongoing risk to users. The domain’s use of a future creation date (June 2026) suggests an attempt to evade automated detection systems that rely on domain age as a trust signal. Recommended response actions include immediate blacklisting at the DNS and network levels, as well as user education to verify governance portals through official Ethena channels. Despite mitigation efforts, the domain’s persistence and proxy-based hosting present a residual risk, necessitating continuous monitoring for shifts in infrastructure or payload delivery.
Data Coverage
Розвіддані з мережевої безпеки
Процес реагування на загрози Pipeline
Перевірка за блок-листами
10 зовнішніх джерел під наглядом · знімок від 11.08.2026
8 зовнішніх джерел під наглядом Збігів немає
Хронологія виявлення
-
Cloudflare Radar
Сканування Cloudflare Radar збережено · Відкрити сканування
Аналітика доменів
Технічні подробиціDNS, імена TLS і часові мітки
ICANN OVERSIGHT
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Технології
Виявлено 3 технології з високою впевненістю
Аналіз VirusTotal
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога