auth-wetransfer-com-4c95d-5d82f-6f882c[.]vercel[.]app
“WeTransfer”
auth-wetransfer-com-4c95d-5d82f-6f882c.vercel.app — المحتوى غير متوفر. انتحال العلامة التجارية: WeTransfer; نوع الاحتيال: Brand Impersonation. ملخص الأدلة: VirusTotal 19/95 (ADMINUSLabs, alphaMountain.ai, BitDefender, Certego, CRDF); URLScan malicious verdict; PhishDestroy score 100/100. مسجّل النطاق: Vercel.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
This domain, auth-wetransfer-com-4c95d-5d82f-6f882c.vercel.app, poses a specific threat of brand impersonation targeting WeTransfer users. The site was designed to mimic the legitimate WeTransfer service, potentially tricking users into divulging sensitive information such as login credentials, personal data, or financial details. Visiting this domain could lead to unauthorized access to user accounts, theft of personal information, and financial losses.
Analysis indicates that the domain is flagged by 19 out of 95 security vendors on VirusTotal, suggesting a high level of suspicion among the security community. The domain was registered through Vercel Inc. and used an SSL certificate issued by Google Trust Services, which can give a false sense of security to unsuspecting users. The IP address associated with this domain, 216.198.79.131, is located in the United States and belongs to AS16509 Amazon.com, Inc. Additionally, the site appears on two security blocklists, PhishDestroy and PhishingDB, further confirming its malicious nature. The domain is currently offline, but the risk remains if it is reactivated.
If a user has visited this domain, they should immediately change their WeTransfer account password and enable two-factor authentication (2FA) if not already enabled. It is also recommended to monitor the account for any unauthorized activity and to notify WeTransfer customer support about the potential breach. Users should be cautious of unexpected emails or messages asking for personal information and verify the authenticity of any communication purportedly from WeTransfer by visiting the official website directly.
مؤشرات الأمان
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
التقنيات · 2 identified
HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org ثقة 100٪تحليل VirusTotal
الأدلة المؤرشفة
الأدلة والتقارير الخارجية
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب