lucky-giftbox18[.]vercel[.]app
“Deployment Unavailable”
lucky-giftbox18.vercel.app — Inhalt nicht verfügbar. Betrugstyp: Generic Phishing. Zusammenfassung der Beweislage: VirusTotal 10/93 (ADMINUSLabs, ChainPatrol, alphaMountain.ai, BitDefender, CyRadar); URLQuery 3 alerts; 3 external blocklist matches (Polkadot, Enkrypt, Codeesura); PhishDestroy score 80/100. Registrar: Tucows.
Die ausführliche Analyse von PhishDestroy AI bleibt auf Englisch, damit der ursprüngliche forensische Bericht unverändert bleibt.
The domain lucky-giftbox18.vercel.app was registered on February 21, 2026 through Tucows Domains Inc. and is currently hosted on Amazon’s infrastructure (AS16509) in the United States, resolving to IP address 64.29.17.131. The site presents an HTTP 451 response with the page title "Deployment Unavailable" and serves a TLS certificate issued by Google Trust Services under the WR1 certificate authority. VirusTotal analysis recorded ten of ninety‑three security vendors flagging the domain as malicious, and the domain is listed on four independent blocklists, specifically PhishDestroy, Polkadot, Enkrypt, and Codeesura.
The presence of Vercel platform identifiers and HSTS enforcement indicates the site leveraged a legitimate cloud service to host the malicious payload. As of the report date, July 24, 2026, the domain has been taken offline, but the historical evidence suggests a high‑risk generic phishing operation. While the specific brand or service being impersonated has not been identified in the available intelligence, the combination of a newly created domain, rapid detection by multiple vendors, and inclusion on several blocklists warrants a high confidence rating for malicious intent.
Defenders should continue to block the domain at perimeter and DNS layers, monitor for any re‑registration attempts, and correlate any related traffic with the observed IP address and certificate fingerprint. Additional investigation of any payloads or URLs referenced in the original deployment would be required to fully characterize the phishing kit, but the current indicators are sufficient to justify preventive controls and incident response escalation.
Erkenntnisse zur Netzwerksicherheit
Pipeline zur Reaktion auf Sicherheitsbedrohungen
Status der öffentlichen Sperrliste
Technologien · 2 identified
Cloud platform for frontend deployment, optimized for Next.js.
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
VirusTotal-Analyse
Website-Performanceanalyse
Google PageSpeed Insights — mobile performance audit of lucky-giftbox18.vercel.app · checked Mar 2, 2026
Nachweise und externe Berichte
Wurden Sie von dieser Website betroffen?
Wenn Sie Kontoanmeldeinformationen, persönliche oder Zahlungsinformationen eingegeben oder eine Datei von dieser Domain heruntergeladen haben, ergreifen Sie sofort Maßnahmen. Nachfolgend finden Sie Ressourcen, die Ihnen helfen, den Vorfall zu melden und sich zu schützen.
Melden Sie sich bei Ihren örtlichen Behörden
Wählen Sie Ihr Land aus, um Offizielle Kontakte im Bereich Cyberkriminalität oder einen Beschwerdeentwurf erstellen → zu erhalten.
Jede beliebige Domain prüfen
Bedrohungsanalyse anhand gespeicherter Blocklisten, WHOIS, DNS und öffentlicher Scan-Beweise
Jetzt scannenPhishing melden
Melden Sie verdächtige Domains an unsere Bedrohungsdatenbank – schützen Sie die Community
MeldenEchtzeit-Bedrohungsfeed
Aktuelle Phishing-Meldungen und beobachtete Verfügbarkeitsänderungen
ÜberwachenBleiben Sie auf dem Laufenden, bleiben Sie sicher
Beobachten Sie aktuelle Bedrohungen oder legen Sie Widerspruch gegen diesen Eintrag ein, wenn Sie der Meinung sind, dass es sich um einen Fehlalarm handelt