nftlucky-box09[.]vercel[.]app
“Deployment Unavailable”
nftlucky-box09.vercel.app — المحتوى غير متوفر. نوع الاحتيال: Nft Scam. ملخص الأدلة: VirusTotal 16/93 (ADMINUSLabs, ChainPatrol, Criminal IP, alphaMountain.ai, ArcSight Threat Intelligence); 3 external blocklist matches (Polkadot, Enkrypt, Codeesura); CF Radar malicious; PhishDestroy score 100/100. مسجّل النطاق: Tucows.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
This domain, nftlucky-box09.vercel.app, operates as a crypto drainer designed to siphon cryptocurrency assets from connected digital wallets. Analysis indicates the site employs deceptive smart contract interactions or malicious transaction prompts to trick users into authorizing unauthorized fund transfers, a tactic increasingly observed in targeted attacks against decentralized finance (DeFi) participants. The domain mimics legitimate NFT or token distribution platforms, leveraging urgency-driven messaging (e.g., "limited-time offers") to exploit victims before they detect the fraudulent activity. Once permissions are granted, the drainer executes automated scripts to empty wallet balances without further user consent, often targeting multiple blockchain networks simultaneously to maximize impact. Infrastructure analysis reveals multiple high-confidence indicators of compromise. The domain resolves to IP address 216.198.79.67, hosted on Amazon Web Services (AS16509), and presents a "Deployment Unavailable" page title, likely a placeholder or fallback state for the malicious payload. It is flagged by 16 out of 95 security vendors on VirusTotal, with additional listings on five specialized blocklists, including those maintained by blockchain security providers. The domain was registered on February 21, 2026, through Tucows Domains Inc., and uses an SSL certificate issued by Google Trust Services (WR1), a common tactic to appear legitimate. The unique seed identifier 8b8ef4 further distinguishes this campaign from other active threats, suggesting coordinated deployment across multiple domains. Users who have interacted with nftlucky-box09.vercel.app should immediately revoke all active smart contract approvals associated with the wallet used on the site. This can be done via blockchain explorers or dedicated revocation tools, ensuring no residual permissions remain. Next, transfer remaining assets to a new, secure wallet address not previously exposed to the domain. Monitor transaction histories for unauthorized activity and report the incident to relevant blockchain security teams or community alert platforms. If private keys or seed phrases were entered, consider the wallet compromised and avoid reusing it. Organizations should update internal blocklists to include this domain and its associated IP, while users should verify all future NFT or token claims through official project channels only.
استخبارات أمن الشبكات
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
التقنيات · 2 identified
Cloud platform for frontend deployment, optimized for Next.js.
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
تحليل VirusTotal
تحليل أداء الموقع
Google PageSpeed Insights — mobile performance audit of nftlucky-box09.vercel.app · checked Mar 2, 2026
الأدلة والتقارير الخارجية
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب