MALICIOUS — CRITICAL
Phishing- und Sicherheitsprüfung für demoeth.vercel.app
demoeth[.]
This domain, demoeth.vercel.app, is flagged as an active crypto scam targeting Ethereum users through a fraudulent ETH AirDrop scheme.
- VirusTotal
- 1/91
- Blocklists
- No stored match
- Verfügbarkeit
- Letzter bekanntermaßen aktiv · HTTP 200
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
demoeth.vercel.app — Letzter bekanntermaßen aktiv (HTTP 200). Markenidentität: Ethereum; Betrugstyp: Crypto Scam. Zusammenfassung der Beweislage: VirusTotal 1/91 (Forcepoint ThreatSeeker); PhishDestroy score 76/100. Registrar: Tucows.
Die ausführliche Analyse von PhishDestroy AI bleibt auf Englisch, damit der ursprüngliche forensische Bericht unverändert bleibt.
Evidence Analysis
This domain, demoeth.vercel.app, is flagged as an active crypto scam targeting Ethereum users through a fraudulent ETH AirDrop scheme. Registered on February 21, 2026, via Tucows Domains Inc., the site resolves to IP 216.198.79.67, hosted on Amazon.com, Inc. infrastructure (AS16509) in the US. The page title explicitly advertises an 'ETH AirDrop,' aligning with known phishing kits classified as Airdrop Scams. SSL certification is provided by Google Trust Services, and the domain is served through Vercel with HSTS enabled, suggesting a structured deployment rather than opportunistic hosting. Analysis indicates the domain is currently active, returning an HTTP 200 status, and has been blocked by at least one security vendor. Gridinsoft assigns a trust score of 0/100, while Scamadviser rates it 21/100, both reflecting high-risk classifications. The domain appears on one security blocklist, though no detections were recorded in the most recent scans by 93 vendors—absence of detections does not confirm legitimacy. Defenders should treat this domain as a confirmed impersonation threat. The infrastructure, including Vercel hosting and Amazon IP allocation, is consistent with scalable phishing operations. Given the explicit branding of an ETH AirDrop and the domain’s recent creation, the site is likely designed to harvest credentials or private keys under false pretenses. Immediate blocking at DNS or proxy level is recommended, alongside monitoring for related subdomains or IP reuse. Further investigation should focus on identifying wallet addresses or redirect chains linked to this campaign.
Stored source results
Recorded verdicts and infrastructure observations for this domain.
Datenabdeckung13 recorded checks
Erkenntnisse zur Netzwerksicherheit
Pipeline zur Reaktion auf Sicherheitsbedrohungen
Status der öffentlichen Sperrliste
Technologien · 2 identified
Cloud platform for frontend deployment, optimized for Next.js.
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
VirusTotal-Analyse
Website-Performanceanalyse
Google PageSpeed Insights — mobile performance audit of demoeth.vercel.app · checked Mar 2, 2026
Nachweise und externe BerichteIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Wenn Sie Kontoanmeldeinformationen, persönliche oder Zahlungsinformationen eingegeben oder eine Datei von dieser Domain heruntergeladen haben, ergreifen Sie sofort Maßnahmen. Nachfolgend finden Sie Ressourcen, die Ihnen helfen, den Vorfall zu melden und sich zu schützen.
Melden Sie sich bei Ihren örtlichen Behörden
Wählen Sie Ihr Land aus, um Offizielle Kontakte im Bereich Cyberkriminalität oder einen Beschwerdeentwurf erstellen → zu erhalten.