MALICIOUS — CRITICAL
Phishing- und Sicherheitsprüfung für minipay-hackathon.vercel.app
minipay-hackathon[.]
This domain is flagged as a high-risk brand impersonation threat specifically targeting MetaMask, a widely used cryptocurrency wallet.
- VirusTotal
- 3/94
- Blocklists
- 2 · MetaMask, SEAL
- Verfügbarkeit
- Getarnt · erreichbar · HTTP 200
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
minipay-hackathon.vercel.app — Getarnt · erreichbar (HTTP 200). Markenidentität: MetaMask; Betrugstyp: Crypto Scam. Zusammenfassung der Beweislage: VirusTotal 3/94 (ChainPatrol, alphaMountain.ai); 2 external blocklist matches (MetaMask, SEAL); cloaking observed; PhishDestroy score 98/100. Registrar: Vercel.
Die ausführliche Analyse von PhishDestroy AI bleibt auf Englisch, damit der ursprüngliche forensische Bericht unverändert bleibt.
Evidence Analysis
This domain is flagged as a high-risk brand impersonation threat specifically targeting MetaMask, a widely used cryptocurrency wallet. The site mimics legitimate wallet interfaces to deceive users into disclosing sensitive credentials or authorizing malicious transactions, potentially leading to unauthorized asset transfers or account compromise. Analysis indicates the domain minipay-hackathon.vercel.app was registered on March 13, 2026, through Vercel Inc. and resolves to the IP address 64.29.17.67, hosted on Amazon.com, Inc. infrastructure (AS16509). The SSL certificate is issued by Google Trust Services (WR1). VirusTotal reports 3 out of 95 security vendors flagging the domain as malicious. It appears on three security blocklists and is actively blocked by multiple threat intelligence platforms. Infrastructure analysis reveals the domain remains operational despite detection. Mitigation steps for this type of threat include immediate blocking of the domain and its associated IP (64.29.17.67) at the network perimeter. Users should be advised to verify wallet addresses and transaction details before execution, particularly when prompted by unsolicited links. Organizations should monitor for outbound connections to the domain or IP and review logs for signs of credential harvesting or unauthorized transaction attempts. Security teams are recommended to update detection rules to include this domain and its indicators in threat feeds.
Stored source results
Recorded verdicts and infrastructure observations for this domain.
Datenabdeckung12 recorded checks
Erkenntnisse zur Netzwerksicherheit
Pipeline zur Reaktion auf Sicherheitsbedrohungen
Status der öffentlichen Sperrliste
Technologien · 2 identified
Cloud platform for frontend deployment, optimized for Next.js.
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
VirusTotal-Analyse
Website-Performanceanalyse
Google PageSpeed Insights — mobile performance audit of minipay-hackathon.vercel.app · checked Mar 13, 2026
Nachweise und externe BerichteIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Wenn Sie Kontoanmeldeinformationen, persönliche oder Zahlungsinformationen eingegeben oder eine Datei von dieser Domain heruntergeladen haben, ergreifen Sie sofort Maßnahmen. Nachfolgend finden Sie Ressourcen, die Ihnen helfen, den Vorfall zu melden und sich zu schützen.
Melden Sie sich bei Ihren örtlichen Behörden
Wählen Sie Ihr Land aus, um Offizielle Kontakte im Bereich Cyberkriminalität oder einen Beschwerdeentwurf erstellen → zu erhalten.