الانتقال إلى تقرير الأمان
Checked 09/08/2026 Ref BB37FEDE

MALICIOUS — CRITICAL

twq.vercel.app — Ethereum Brand Impersonation Report

twq[.]vercel[.]app

The domain twq.vercel.app is currently flagged as a high-risk brand impersonation threat, specifically targeting the Ethereum brand.

100/100 evidence score · Critical
VirusTotal
11/91
Blocklists
2 · MetaMask, SEAL
التوفر
آخر نشاط معروف · HTTP 308
Report / Add Evidence Appeal this listing
2026-05-22 07:29 UTCآخر نشاط معروف · HTTP 308

Do not enter credentials, seed phrases, payment details, or personal information on this domain.

⚠️
تم الإبلاغ عن هذا النطاق باعتباره ضارًّا
محركات الأمان التي تبلغ عن اكتشاف: 11. قوائم الحظر العامة التي تبلغ عن تطابق: 2. توخي الحذر الشديد — لا تدخل بيانات الاعتماد أو المعلومات الشخصية.
Jump to section
ملخص التقرير

twq.vercel.app — آخر نشاط معروف (HTTP 308). انتحال العلامة التجارية: Ethereum; نوع الاحتيال: Brand Impersonation. ملخص الأدلة: VirusTotal 11/91 (ADMINUSLabs, ChainPatrol, alphaMountain.ai, ESET, Emsisoft); URLQuery 4 alerts; URLScan malicious verdict; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 100/100. مسجّل النطاق: Vercel.

يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.

Evidence Analysis

Ref BB37FEDE

The domain twq.vercel.app is currently flagged as a high-risk brand impersonation threat, specifically targeting the Ethereum brand. The site was created on May 22, 2026, and is hosted via Vercel Inc., a legitimate platform often abused by phishers. The page title shows "Redirecting...", suggesting it may redirect users to other malicious pages. No specific drainer kit has been identified in the available data, but the impersonation of a major cryptocurrency brand strongly indicates credential or wallet theft attempts.

Technical indicators reveal critical red flags. VirusTotal reports 11 out of 95 security vendors flagging this domain as malicious, providing a strong consensus of risk. The domain resolves to IP address 216.198.79.67 and uses an SSL certificate from Google Trust Services (WR1). It currently appears on 3 security blocklists. The registrar is Vercel Inc., and the domain creation date is May 22, 2026. Google Safe Browsing status is not explicitly stated, but the high blocklist count and VT scores suggest it may be listed. These indicators collectively point to an active phishing infrastructure designed to deceive users into revealing sensitive information.

As of this report, twq.vercel.app remains active and accessible, posing an ongoing risk to users who may encounter it through deceptive emails, ads, or search results. PhishDestroy recommends immediate blocking of this domain at the network level. Users should avoid interacting with the site and ensure their crypto wallets and credentials are secure. If any exposure has occurred, immediate password changes and wallet migration are advised. Further monitoring is required as the threat may evolve or redirect to other domains. The remaining risk is high due to the domain's active status and strong impersonation of a trusted brand like Ethereum.

Stored source results

Recorded verdicts and infrastructure observations for this domain.

VirusTotal
VirusTotal
11 det.
URLQuery
URLQuery
4 threat alerts
DNS Security
1/14
شهادة TLS
Google Trust Services
Hosting
Vercel
العمر
3 mo New
الحالة المرصودة
آخر نشاط معروف 308
PhishDestroy
قائمة الإتلاف
مُدرج
نطاق تغطية البيانات12 recorded checks
VirusTotal 11 / 91 URLQuery 4 threat-system alerts PhishStats checked — no match recorded OTX no community references رادار CF scan completed URLScan capture التقرير المخزن URLScan verdict malicious حجب عناوين DNS 1/14 TLS valid certificate, 65d WHOIS 3 mo old لقطة شاشة 3 captures · 3 sources سلسلة إعادة التوجيه لم يتم التحقيق فيها
استخبارات أمن الشبكات
DNS Provider Blocks 1 / 14
Quad9 Secure
Threat Detection Systems 4 alerts
Detection System Indicator Verdict Alert
OpenDNS bafybeihcsysneyswz74k2yucjnjhlsem373t6vvev7jyakyshvaor4hb5a.ipfs.inbrowser.link phishing Phishing Block
DNS4EU bafybeihcsysneyswz74k2yucjnjhlsem373t6vvev7jyakyshvaor4hb5a.ipfs.inbrowser.link malicious Sinkholed
Quad9 DNS bafybeihcsysneyswz74k2yucjnjhlsem373t6vvev7jyakyshvaor4hb5a.ipfs.inbrowser.link malicious Sinkholed
Quad9 DNS twq.vercel.app malicious Sinkholed
Free Hosting Detected Vercel
This domain is hosted on Vercel (free hosting platform). Free hosting platforms are commonly used for both legitimate testing/development and malicious purposes. Additional context is needed for a def

مسار الاستجابة للتهديدات Pipeline

الاكتشاف
Checks
Reports
التوفر
14/16
تم استيعاب التهديد
twq.vercel.app تم اكتشافها وإدراجها في قائمة الانتظار لإجراء تحليل شامل
22/05/2026
URLScan.io Capture
Stored URLScan report with capture artifacts
URLScan Verdict
URLScan returned a malicious verdict · score 100
29/07/2026
Cloudflare Radar Report
A stored Cloudflare Radar report is available. The report link alone is not a malicious verdict and does not prove that every network field was captured.
Web Archive
Preserved in آلة الزمن — historical evidence archived
24/05/2026
VirusTotal
11/91 recorded on VirusTotal
18/07/2026
Google Safe Browsing
22/05/2026
الكشف عن قوائم الحظر
موجود في 2 blocklists: MetaMask, SEAL
09/08/2026
DNS Security Blocks
Blocked by 1 of 14 checked DNS providers: Quad9 secure
Free Hosting: Vercel
Site hosted on Vercel — free hosting platforms are frequently used for throwaway phishing sites
Brand Impersonation
Impersonation of Ethereum
Forensic Evidence Collected
Stored evidence from URLScan.io, URLQuery, stored screenshot
Technical Analysis Recorded
يحتوي التقرير على التكنولوجيا المخزنة أو نتائج تحليل الطب الشرعي.
09/08/2026
Complaint Draft Available
لا يتم تسجيل أي تقديم. يمكنك إنشاء مسودة ومراجعتها وتقديمها بنفسك إلى السلطة المختصة.
تم نشر قائمة «DestroyList»
22/05/2026
Monitoring Continues
يظل المجال قابلاً للوصول أو مقيد الوصول؛ قد تؤدي الفحوصات المستقبلية إلى تحديث هذه الملاحظة.

حالة قوائم الحظر العامة

لقطة محفوظة

معلومات النطاق

النطاق
URLScan Verdict ضار score 100 Phishing report ↗
الخادم / ASN Vercel · AS16509 Amazon.com, Inc.
IP Context Vercel shared edge origin IP hidden لا تُنسب سمعة Edge-IP إلى هذا المجال.
مزود المنصة Vercel US(US)
جهة الإبلاغ عن إساءة الاستخدامabuse@vercel.com
عنوان IP 216.198.79.67 CDN
الموقع الجغرافيUS Cleveland, US
الشبكةAS16509 · CYPRESS COMMUNICATIONS, LLC
يتم إخفاء عنوان IP الأصلي خلف وكيل CDN. تحتوي نتائج IP العكسي لعنوان الحافة على مستأجرين غير مرتبطين؛ يتطلب العثور على المصدر نظام أسماء النطاقات السلبي أو بيانات شفافية الشهادة.
حالة HTTP308 Permanent Redirect
Elapsed Since First Report 50 days
ما الذي نحتسبه Raw elapsed time since the first stored abuse report. It is not a registrar response-time measurement. Latest observed status: آخر نشاط معروف.
ما يحتويه كل تقرير قد تشير سجلات التقارير الصادرة المخزنة إلى الأدلة المتاحة في ذلك الوقت، مثل أحكام البائعين أو بيانات التسجيل أو تفاصيل الاستضافة أو التصنيفات أو لقطات الشاشة. لا تستنتج هذه الصفحة الحمولة الدقيقة التي تم تسليمها أو استلامها أو إقرارها أو الإجراء الذي اتخذه المستلم.
التفاصيل الفنيةDNS، أسماء المجال البديلة (SAN) في بروتوكول SSL، الطوابع الزمنية
تاريخ أول اكتشاف22/05/2026
IoC Extractionscanned 29/07/20260 wallet · 0 Telegram IoCs
Submitted URLhttp://twq.vercel.app/
TLS Fingerprint
TLS Observationvalid from 28/04/2026scanned 22/05/2026
TLS SAN Domainsvercel.app
عنوان الصفحة
Redirecting...
شهادة TLS
Valid transport encryption · صادرة عن Google Trust Services · valid for 65 days
التقنيات · 3 identified
IPFS
Network storage

IPFS is a peer-to-peer hypermedia protocol that provides a distributed hypermedia web.

ipfs.tech ثقة 100٪
Cloudflare
CDN

Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.

www.cloudflare.com ثقة 100٪
HTTP/3
Miscellaneous

HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.

httpwg.org ثقة 100٪
Detected via رادار Cloudflare · Wappalyzer engine
الإبلاغ عن هذا النطاق أرسل الأدلة وساعد في حماية الآخرين

تحليل VirusTotal

11 / قام موردو الأمان 91 بوضع علامة على هذا المجال
View on VT
Last analyzed
ADMINUSLabs
ChainPatrol
alphaMountain.ai
ESET
Emsisoft
Fortinet
G-Data
كاسبرسكي
نتكرافت
سوفوس
Webroot

الأدلة المؤرشفة

Wayback Machine Snapshot
لقطة تاريخية متاحة لمراجعة الأدلة
View Archive
تحليل أداء الموقع

Google PageSpeed Insights — mobile performance audit of twq.vercel.app · checked May 22, 2026

72
Needs Work
Performance
FCP
2.44s
First Contentful Paint
LCP
24.92s
Largest Contentful Paint
CLS
0.001
Cumulative Layout Shift
TBT
23ms
Total Blocking Time
SI
2.44s
Speed Index
Powered by Google PageSpeed Insights · Mobile strategy · Scores: 90-100 Good 50-89 Needs Work 0-49 Poor
الأدلة والتقارير الخارجيةIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
If credentials were compromised, report immediately. Do not engage with recovery scammers.

إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.

اليوروبول
ابحث عن قناة التقارير الرسمية لبلدك في الاتحاد الأوروبي
National police directory
احذروا من المحتالين الذين يزعمون أنهم يساعدون في استرداد الأموال! قد يتصل المجرمون بالضحايا مرة أخرى بينما يتظاهرون بأنهم محققون أو محامون أو وكلاء استرداد. لا تدفع رسومًا مقدمة أو تشارك بيانات الاعتماد. تعرف على المزيد حول الاحتيال في مجال التعافي →

أبلغ السلطات المحلية

حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.

دليل 97 دولة
المسودة بمساعدة الذكاء الاصطناعي - تتم معالجة تفاصيل الحادث بواسطة موفر الذكاء الاصطناعي قم بمراجعتها وتقديمها بنفسك
تضمين هذا التقريرRead-only HTML widget
HTML · IFRAME

تضمين هذا التقرير

شارك هذه المعلومات الاستخباراتية المتعلقة بالتهديدات على موقعك الإلكتروني أو مدونتك

embed.html
<iframe
  src="https://phishdestroy.io/ar/embed/domain/twq.vercel.app"
  title="PhishDestroy threat report for twq.vercel.app"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>