vote-fogo.xyz
vote-fogo.xyz 被识别为冒充 MetaMask 品牌的钱包盗取器,通过伪造登录面板诱导用户授权。该域名由 NICENIC INTERNATIONAL GROUP CO., LIMITED 注册,托管于 Cloudflare 网络(IP: 104.21.84.113),VirusTotal 检测率为 2/89
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
证据摘要
vote-fogo.xyz 于 2026-08-31 被首次观测,并在 2026-09-09 的 VirusTotal 快照中记录 2/89 的检测率,同时被 MetaMask 和 SEAL 黑名单收录。该域名冒充 MetaMask 钱包服务,通过仿冒登录界面诱导用户输入助记词或授权交易,从而盗取加密货币资产。攻击者利用 Cloudflare 的 CDN 服务隐藏真实服务器位置,增加追踪难度。用户应避免在该域名输入任何敏感信息,并仅通过官方渠道访问钱包服务。
网络安全情报 Registrar context
Forensic History & Detection Timeline
-
Domain Status Transition Sep 14, 2026 · 00:18 UTCDomain state transitioned from dead to alive.
-
Domain Status Transition Sep 13, 2026 · 00:54 UTCDomain state transitioned from alive to dead.
-
Domain Status Transition Sep 12, 2026 · 00:18 UTCDomain state transitioned from dead to alive.
-
Domain Status Transition Sep 11, 2026 · 12:22 UTCDomain state transitioned from alive to dead.
-
Domain Status Transition Sep 11, 2026 · 00:17 UTCDomain state transitioned from dead to alive.
-
Domain Status Transition Sep 10, 2026 · 04:45 UTCDomain state transitioned from alive to dead.
-
Domain Status Transition Sep 9, 2026 · 03:00 UTCDomain state transitioned from alive to dead.
-
Threat First Observed Sep 9, 2026 · 01:13 UTCDomain ingestion complete. Initial state is marked as alive.
威胁响应 Pipeline
公共封禁名单状态
Evasion analysis
Cloaking & traffic-distribution check
Stored crawler-versus-browser observations for this host, plus a live fingerprint check for Keitaro-style traffic distribution systems.
- Stored cloaking flag
- Not yet scanned
- Last cloaking scan
- Server header seen by scanner
cloudflare
Scanner note: alive_content: raw=ok; http=200; via=https_proxy; server=cloudflare
已保存的截图 · 1 source
域名情报
技术详情DNS、SSL SAN、时间戳
ICANN OVERSIGHT
认证和 RAA 背景
认证和 RAA 背景
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Latest Classified Outcome 2026-09-20 02:37:50 UTC
技术 · 2 identified
VirusTotal 分析
仿冒域名
已存储 79 个仿冒域名
显示全部(67)
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。