Zum Sicherheitsbericht springen
Checked 09.08.2026 Ref 18E93C9A

MALICIOUS — CRITICAL

Phishing- und Sicherheitsprüfung für cross-pay.vercel.app

cross-pay[.]vercel[.]app

Analysis of the domain cross-pay.vercel.app indicates confirmed brand impersonation targeting Across Protocol, a known cross-chain bridge service.

92/100 evidence score · Critical
VirusTotal
9/94
Blocklists
2 · MetaMask, SEAL
Verfügbarkeit
Getarnt · erreichbar · HTTP 200
Report / Add Evidence Appeal this listing
2026-03-24 11:29 UTCGetarnt · erreichbar · HTTP 200

Do not enter credentials, seed phrases, payment details, or personal information on this domain.

⚠️
Diese Domain wurde als bösartig markiert.
Sicherheits-Engines melden eine Entdeckung: 9. Öffentliche Blocklisten, die eine Übereinstimmung melden: 2. Seien Sie äußerst vorsichtig – Geben Sie keine Anmeldeinformationen oder persönlichen Daten ein.
Jump to section
Berichtsübersicht

cross-pay.vercel.app — Getarnt · erreichbar (HTTP 200). Markenidentität: Across; Betrugstyp: Wallet/seed Phishing. Zusammenfassung der Beweislage: VirusTotal 9/94 (ChainPatrol, alphaMountain.ai, BitDefender, CyRadar, ESET); 2 external blocklist matches (MetaMask, SEAL); cloaking observed; PhishDestroy score 92/100. Registrar: Vercel.

Die ausführliche Analyse von PhishDestroy AI bleibt auf Englisch, damit der ursprüngliche forensische Bericht unverändert bleibt.

Evidence Analysis

Ref 18E93C9A

Analysis of the domain cross-pay.vercel.app indicates confirmed brand impersonation targeting Across Protocol, a known cross-chain bridge service. The domain was registered on March 13, 2026, through Vercel Inc. and remains active as of July 12, 2026. Infrastructure analysis reveals it resolves to IP address 64.29.17.131 and is hosted on Vercel's platform, with HSTS enabled. The domain appears on three security blocklists and is explicitly blocked by SEAL, MetaMask, and PhishDestroy, confirming its malicious classification. VirusTotal detection data shows 9 of 95 security vendors flagging the domain as malicious, though this represents a minority of engines and should not be interpreted as definitive proof of compromise. The SSL certificate is issued by Google Trust Services, which does not inherently indicate legitimacy given the prevalence of free, automated certificate issuance. Gridinsoft assigns a trust score of 0/100, further supporting its classification as high-risk. No specific phishing kit or exact page content has been analyzed, so the precise mechanics of the scam remain unconfirmed. However, the combination of brand impersonation, recent registration, and active blocking by multiple security vendors strongly suggests credential harvesting or fraudulent transaction activity. Defenders should treat this domain as malicious and implement blocking measures at the DNS or network level. Given its continued activity, monitoring for related infrastructure (e.g., subdomains, linked IPs) is recommended.

Stored source results

Recorded verdicts and infrastructure observations for this domain.

VirusTotal
VirusTotal
9 det.
URLScan
URLScan
TLS-Zertifikat
Google Trust Services
Hosting
Vercel
Alter
5 mo
Beobachteter Status
Getarnt · erreichbar 200
PhishDestroy
DestroyList
Gelistet
Datenabdeckung12 recorded checks
VirusTotal 9 / 94 URLQuery Bericht gespeichert – detailliertes Urteil steht noch aus PhishStats checked — no match recorded OTX no community references CF-Radar scan completed URLScan capture gespeicherter Bericht URLScan verdict Bewertung nicht verfügbar DNS-Sperren 14 geprüft — keine Sperren TLS valid certificate, 75d WHOIS 5 mo old Screenshot 2 captures · 2 sources Weiterleitungskette nicht untersucht
Erkenntnisse zur Netzwerksicherheit
Free Hosting Detected Vercel
This domain is hosted on Vercel (free hosting platform). Free hosting platforms are commonly used for both legitimate testing/development and malicious purposes. Additional context is needed for a def

Pipeline zur Reaktion auf Sicherheitsbedrohungen

Entdeckung
Checks
Reports
Verfügbarkeit
12/14
Bedrohung erkannt
cross-pay.vercel.app erkannt und für eine vollständige Analyse in die Warteschlange gestellt
13.03.2026
URLScan.io Capture
Stored URLScan report with capture artifacts
24.03.2026
Cloudflare Radar Report
A stored Cloudflare Radar report is available. The report link alone is not a malicious verdict and does not prove that every network field was captured.
VirusTotal
9/94 recorded on VirusTotal
18.07.2026
Google Safe Browsing
13.07.2026
Erkennung von Blocklisten
Gefunden in 2 blocklists: MetaMask, SEAL
09.08.2026
Free Hosting: Vercel
Site hosted on Vercel — free hosting platforms are frequently used for throwaway phishing sites
Brand Impersonation
Impersonation of Across
Forensic Evidence Collected
Stored evidence from URLScan.io, stored screenshot
24.03.2026
Technical Analysis Recorded
Der Bericht enthält gespeicherte Technologie- oder forensische Analyseergebnisse.
09.08.2026
VT detections increased by 5
+5 new detections (4 → 9): BitDefender, CyRadar, Forcepoint ThreatSeeker, Fortinet +2
13.07.2026
Complaint Draft Available
Es wird keine Einreichung aufgezeichnet. Sie können einen Entwurf erstellen, ihn überprüfen und ihn selbst bei der zuständigen Behörde einreichen.
DestroyList veröffentlicht
13.03.2026
Monitoring Continues
Die Domäne bleibt erreichbar oder zugriffsbeschränkt; Zukünftige Überprüfungen könnten diese Beobachtung aktualisieren.

Status der öffentlichen Sperrliste

Gespeicherte Aufnahme

Domain-Intelligenz

Domain
Server / ASN Vercel · AS16509 AMAZON-02 - Amazon.com, Inc., US
IP Context Vercel shared edge origin IP hidden Die Edge-IP-Reputation wird dieser Domäne nicht zugeordnet.
Plattformanbieter Vercel US(US)
Abuse-Kontaktabuse@vercel.com
IP-Adresse 64.29.17.131 CDN
StandortUS Walnut, US
NetzwerkAS16509 · Amazon.com, Inc.
Die Ursprungs-IP ist hinter einem CDN-Proxy verborgen. Reverse-IP-Ergebnisse für die Edge-Adresse enthalten nicht verwandte Mandanten; Um den Ursprung zu finden, sind passive DNS- oder Zertifikatstransparenzdaten erforderlich.
Cloaking Cloaking Detected Content split · score 1/6
alive_content: raw=ok; http=200; via=https_proxy; server=Vercel
server: Vercel
checked 09.08.2026
HTTP-Status200
Technische DetailsDNS, SSL-SANs, Zeitstempel
Erstmals entdeckt13.03.2026
DOM Analysisanalyzed 24.03.2026score 15/1002 brand signals
IoC Extractionscanned 29.07.20260 wallet · 0 Telegram IoCs
Submitted URLhttp://cross-pay.vercel.app/
TLS Fingerprint
TLS Observationvalid from 26.02.2026scanned 15.03.2026
TLS SAN Domainsvercel.app
Favicon Hash
Impersonates
Across MetaMask
TLS-Zertifikat
Valid transport encryption · Ausgestellt von Google Trust Services · valid for 75 days
Technologien · 2 identified
Vercel
PaaS CDN

Cloud platform for frontend deployment, optimized for Next.js.

HSTS
Sicherheit

HTTP Strict Transport Security — forces browsers to use HTTPS connections only.

Detected via Cloudflare Radar · Wappalyzer engine
Diese Domain melden Reichen Sie Beweismaterial ein und helfen Sie mit, andere zu schützen

VirusTotal-Analyse

9 / 94 Sicherheitsanbieter haben diese Domain markiert
View on VT
Last analyzed Previous stored snapshot: 4 detections
ChainPatrol
alphaMountain.ai
BitDefender
CyRadar
ESET
Forcepoint ThreatSeeker
Fortinet
G-Data
Sophos
Website-Performanceanalyse

Google PageSpeed Insights — mobile performance audit of cross-pay.vercel.app · checked Jul 13, 2026

96
Good
Performance
FCP
1.05s
First Contentful Paint
LCP
2.7s
Largest Contentful Paint
CLS
0
Cumulative Layout Shift
TBT
0ms
Total Blocking Time
SI
2.68s
Speed Index
Powered by Google PageSpeed Insights · Mobile strategy · Scores: 90-100 Good 50-89 Needs Work 0-49 Poor
Nachweise und externe BerichteIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
If credentials were compromised, report immediately. Do not engage with recovery scammers.

Wenn Sie Kontoanmeldeinformationen, persönliche oder Zahlungsinformationen eingegeben oder eine Datei von dieser Domain heruntergeladen haben, ergreifen Sie sofort Maßnahmen. Nachfolgend finden Sie Ressourcen, die Ihnen helfen, den Vorfall zu melden und sich zu schützen.

Europol
Finden Sie den offiziellen Meldekanal für Ihr EU-Land
National police directory
Vorsicht vor Betrügern, die mit der Rückforderung von Geldern locken! Kriminelle nehmen unter Umständen erneut Kontakt zu Opfern auf und geben dabei vor, Ermittler, Anwälte oder Beitreibungsbeamte zu sein. Zahlen Sie keine Vorabgebühren und geben Sie keine Anmeldeinformationen weiter. Erfahren Sie mehr über Betrug im Zusammenhang mit Wiederaufbaumaßnahmen →

Melden Sie sich bei Ihren örtlichen Behörden

Wählen Sie Ihr Land aus, um Offizielle Kontakte im Bereich Cyberkriminalität oder einen Beschwerdeentwurf erstellen → zu erhalten.

97-Länder-Verzeichnis
KI-gestützter Entwurf – Vorfalldetails werden vom KI-Anbieter verarbeitet Überprüfen Sie es und reichen Sie es selbst ein
Diesen Bericht einbettenRead-only HTML widget
HTML · IFRAME

Diesen Bericht einbetten

Teilen Sie diese Bedrohungsinformationen auf Ihrer Website oder in Ihrem Blog

embed.html
<iframe
  src="https://phishdestroy.io/de/embed/domain/cross-pay.vercel.app"
  title="PhishDestroy threat report for cross-pay.vercel.app"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>