vote-ethena.pro
vote-ethena.pro 被识别为冒充 MetaMask 的钓鱼站点,部署了钱包盗取器(drainer),旨在劫持用户数字资产。该域名由 NICENIC INTERNATIONAL GROUP CO., LIMITED 注册,托管于 CloudFlare 网络(IP: 188.114.96.9),VirusTot
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
证据摘要
该恶意域名 vote-ethena.pro 通过高度仿冒 MetaMask 官方界面,诱导受害者连接加密货币钱包并授权恶意交易,从而触发钱包盗取器(drainer)将资产转移至攻击者控制的地址。其注册于 NICENIC INTERNATIONAL GROUP CO., LIMITED,并利用 CloudFlare 的 CDN 服务(188.114.96.9)隐藏真实服务器,以规避安全检测。VirusTotal 仅 2/89 的极低检出率表明其具备较强的免杀能力,对不熟悉官方域名细节的用户构成严重威胁。安全团队应将该域名列入监控黑名单,并提醒用户警惕任何要求连接钱包的仿冒页面。
网络安全情报 Registrar context
Forensic History & Detection Timeline
-
Domain Status Transition Sep 17, 2026 · 13:02 UTCDomain state transitioned from alive to dead.
-
Domain Status Transition Sep 15, 2026 · 00:19 UTCDomain state transitioned from dead to alive.
-
Domain Status Transition Sep 14, 2026 · 00:22 UTCDomain state transitioned from alive to dead.
-
Domain Status Transition Sep 13, 2026 · 00:18 UTCDomain state transitioned from dead to alive.
-
Domain Status Transition Sep 12, 2026 · 13:03 UTCDomain state transitioned from alive to dead.
-
Domain Status Transition Sep 11, 2026 · 00:17 UTCDomain state transitioned from dead to alive.
-
Domain Status Transition Sep 10, 2026 · 04:45 UTCDomain state transitioned from alive to dead.
-
Domain Status Transition Sep 9, 2026 · 03:00 UTCDomain state transitioned from alive to dead.
-
Threat First Observed Sep 9, 2026 · 01:13 UTCDomain ingestion complete. Initial state is marked as alive.
威胁响应 Pipeline
公共封禁名单状态
Evasion analysis
Cloaking & traffic-distribution check
Stored crawler-versus-browser observations for this host, plus a live fingerprint check for Keitaro-style traffic distribution systems.
- Stored cloaking flag
- Not yet scanned
- Last cloaking scan
- Server header seen by scanner
cloudflare
Scanner note: alive_content: raw=ok; http=200; via=https_proxy; server=cloudflare
Latest Classified Outcome 2026-09-20 02:43:22 UTC
技术 · 2 identified
VirusTotal 分析
仿冒域名
已存储 79 个仿冒域名
显示全部(67)
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。