Security Scan Report: ponsvote-listingv1.netlify.app

Redirected to:
https://ponsvote-listingv1.netlify.app/
Site favicon
Submitted: Sep 22, 2026, 2:50:11 AMCompleted: Sep 22, 2026, 2:50:31 AMpubliccompleted

This website contacted 6 IPs in 3 countries across 5 domains to perform 17 HTTP transactions. The main domain is ponsvote-listingv1.netlify.app and was registered 4 days ago.

Submitted URL: http://ponsvote-listingv1.netlify.app/

Effective URL:

https://ponsvote-listingv1.netlify.app/
Redirected

AI Security Verdict

High Risk

Confidence: 75%

7
Risk Score

Crypto vote/listing dApp on an unranked netlify.app subdomain that triggers a CRITICAL EtherHiding malware IDS alert, uses eval()/Function() code generation and contacts a random .xyz domain. No credential form, but strong malware-loader indicators — avoid.

Risk Factors
CRITICAL network IDS malware alert (EtherHiding exfiltration)
eval() and Function() constructor code generation with external network targets
External link to randomly-generated .xyz domain
Blockchain-contract retrieval pattern matching EtherHiding loader behaviour
Unknown-age, unranked netlify.app subdomain presenting a crypto wallet-connect app
Domain age information unavailable

Details

Page Title

pons – Vote your token to get listed

Scan Type

public

Domain Name Analysis

The domain 'ponsvote-listingv1.netlify.app' uses the application-focused generic top-level domain (.app) with subdomain 'ponsvote-listingv1'. The second-level label 'netlify' is 7 characters long containing two vowels alongside 5 consonants. Tokenizing the label suggests 3 words: net, li, fy. Median word length is 2 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of http://ponsvote-listingv1.netlify.app/

Page Load Overview

0.61s
Total Load Time
283 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en
Text Length:1,095 chars
Detector Agreement:50%

Website Classification

Primary Category

forum community discussion85% confidence
Type: static
Method: ml+structural

All Detected Categories

forum community discussion
85%
cryptocurrency blockchain
80%
documentation technical
69%
technology software
67%
government public service
64%

Detected Features

OG: website

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
763.176.8.218Aws · CLOUDFrankfurt am Main, Hesse, Germany
AS16509Amazon.com, Inc.
2142.250.154.95Google · CDNUnited States
AS15169Google LLC
235.157.26.135Aws · CLOUDFrankfurt am Main, Hesse, Germany
AS16509Amazon.com, Inc.
2142.251.20.94Google · CDNUnited States
AS15169Google LLC
234.243.96.12Aws · CLOUDDublin, Leinster, Ireland
AS16509Amazon.com, Inc.
2104.21.23.179Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
176--

Detected Technologies1

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1E5F141B3F4E0542B5212C28ABB61BB1BFDA2E907D6C98452B2ED07D90F93E83D44350D

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

192:TxORQ/1Z/Q9B20vf1r96mAD/dANsuPGDhETLmRXm+:TxORQ/1Z/Q9B20vth6mADlWstEGRXN

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:7510:IBCA/hTQgwkkAdlQEMIVMIghYJEqFGZCwBBFoAIohFCu2tIlMARUeAnAQIiEZJWgBAKCQYpQI0AiEP0ppA6TRFaQgSEEK2AS

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:067076363c2c3c3d
Perceptual Hash:8264ef1dbc9434d9
Difference Hash:94c3c5c4d1d5c9e5
Wavelet Hash:077171273d213d3d
Color Hash:#78763a

Other Hashes

Crop Resistant:94c3c5c4d1d5c9e5

Scan History

Scan history not available

Unable to load historical scan data