detran-espirito-santo-govbr-ipva[.]vercel[.]app
“Serviços DETRAN-ES Veículos”
detran-espirito-santo-govbr-ipva.vercel.app — مغطى بعباءة · يمكن الوصول إليه. نوع الاحتيال: Generic Phishing. ملخص الأدلة: VirusTotal 2/91 (ADMINUSLabs, Fortinet); cloaking observed; PhishDestroy score 61/100. مسجّل النطاق: Vercel.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
PhishDestroy identifies an active generic phishing campaign using the domain detran-espirito-santo-govbr-ipva.vercel.app, which impersonates Brazil’s Departamento Estadual de Trânsito do Espírito Santo (DETRAN-ES) IPVA payment portal. The threat does not employ a known drainer kit but relies on visual spoofing to trick users into submitting sensitive personal and financial information. The domain’s naming convention closely mirrors legitimate government portals, increasing the risk of successful deception among Portuguese-speaking users seeking to pay vehicle taxes. This domain resolves to IP address 216.198.79.195 and was registered through Vercel Inc. As of the latest scan, it shows 0 detections on VirusTotal out of 95 engines, indicating it remains undetected by most antivirus solutions. It utilizes a Google Trust Services SSL certificate, which may lend false legitimacy to users. The domain does not appear on known blocklists at this time, and its creation date is not publicly disclosed due to Vercel's privacy protections. The lack of detection and use of a reputable hosting provider (Vercel) and CA (Google Trust Services) suggests this campaign is actively evolving to evade defenses. This domain is currently active and poses a credible threat to individuals attempting to access DETRAN-ES IPVA services. PhishDestroy has flagged this domain with unique seed e6428b and continues to monitor its infrastructure for changes in hosting or certificate issuance. Users are strongly advised to verify the official DETRAN-ES website (detran.es.gov.br) before entering any personal or payment information. Do not click links in unsolicited emails or SMS messages claiming to be from DETRAN-ES. Block the domain at the network level and report any incidents to relevant cybersecurity authorities. While the immediate risk is classified as under investigation, the absence of detections and legitimate appearance warrant heightened caution and proactive blocking.
استخبارات أمن الشبكات
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
التقنيات · 3 identified
HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org ثقة 100٪تحليل VirusTotal
تحليل أداء الموقع
Google PageSpeed Insights — mobile performance audit of detran-espirito-santo-govbr-ipva.vercel.app · checked Apr 27, 2026
الأدلة والتقارير الخارجية
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب