Security Scan Report: ponsvote-listingv1.netlify.app

Site favicon
Submitted: Sep 29, 2026, 3:50:40 AMCompleted: Sep 29, 2026, 3:51:15 AMpubliccompleted

AI Security Verdict

Confirmed Scam

Confidence: 88%

9
Risk Score

Unranked netlify.app subdomain reported as a crypto wallet drainer, loading a ClearFake-flagged external script with a critical EtherHiding malware IDS alert. Do not connect a wallet or sign anything.

Risk Factors (6)
Content-malware threat-intel match (wallet drainer) on the primary domain
Critical network IDS malware alert (EtherHiding Exfil)
Third-party ClearFake-malicious domain contacted by page scripts
Wallet-connection prompt on an unranked, instant-publish netlify.app subdomain
Obfuscated dynamic code execution (eval/Function constructor) on the page
No verifiable business identity beyond a bare 'Pons Labs, LLC' string
Domain age information unavailable

Details

Page Title

pons – Vote your token to get listed

Scan Type

public

Domain Name Analysis

The domain 'ponsvote-listingv1.netlify.app' uses the application-focused generic top-level domain (.app), featuring subdomain 'ponsvote-listingv1'. The second-level label 'netlify' is 7 characters long containing 2 vowels alongside five consonants. Word splitting yields 3 words: net, li, fy. Median word length comes out to 2 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://ponsvote-listingv1.netlify.app/

Page Load Overview

0.76s
Total Load Time
2.0 MB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en
Text Length:1,095 chars
Detector Agreement:50%

Website Classification

Primary Category

forum community discussion85% confidence
Type: static
Method: ml+structural

All Detected Categories

forum community discussion
85%
cryptocurrency blockchain
80%
documentation technical
69%
technology software
67%
government public service
64%

Detected Features

OG: website

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
263.176.8.218Aws · CLOUDFrankfurt am Main, Hesse, Germany
AS16509Amazon.com, Inc.
2142.251.20.95Google · CDNUnited States
AS15169Google LLC
2142.251.14.94Google · CDNUnited States
AS15169Google LLC
2108.133.199.184Aws · CLOUDDublin, Leinster, Ireland
AS16509Amazon.com, Inc.
2172.67.212.118Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
291.98.216.150Falkenstein, Saxony, Germany
AS24940Hetzner Online GmbH
2104.20.35.94Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
235.157.26.135Aws · CLOUDFrankfurt am Main, Hesse, Germany
AS16509Amazon.com, Inc.
2142.251.110.95Google · CDNUnited States
AS15169Google LLC
263.32.191.96Aws · CLOUDDublin, Leinster, Ireland
AS16509Amazon.com, Inc.
2814--

Detected Technologies3

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T121D2D67361B35567601BA59D37A6B7CA7433D303E202DAA07AED03D48F92C4B58A375C

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

768:VmW+fXoFoSJ/h6maiL0gtdIXFDk8Wu6HkvywytK321oX:z+f4Ks0gtiuZ3K

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:28866:NUQGkQwKEWmIRQAMHRBMAIE4aCha0qBbJiEMCicIAKgXQCUCMY6iQBCsGAAUiMIg+CIWpoAhYeEITC4YFADSOEkAOKrwtoAC

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:067076363c2c3c3d
Perceptual Hash:8264ef1dbc9434d9
Difference Hash:94c3c5c4d1d5c9e5
Wavelet Hash:077171273d213d3d
Color Hash:#e08b6c

Other Hashes

Crop Resistant:94c3c5c4d1d5c9e5

Scan History

Scan history not available

Unable to load historical scan data