safelock-web[.]vercel[.]app
“Safelock”
safelock-web.vercel.app — Getarnt · erreichbar. Betrugstyp: Crypto Scam. Zusammenfassung der Beweislage: VirusTotal 9/91 (ChainPatrol, alphaMountain.ai, BitDefender, CyRadar, ESET); 2 external blocklist matches (MetaMask, SEAL); cloaking observed; PhishDestroy score 98/100. Registrar: Vercel.
Die ausführliche Analyse von PhishDestroy AI bleibt auf Englisch, damit der ursprüngliche forensische Bericht unverändert bleibt.
This domain, safelock-web.vercel.app, is flagged as a high-risk crypto wallet phishing resource targeting users through credential harvesting and wallet-draining mechanisms. The page title, "Safelock," suggests an attempt to impersonate legitimate cryptocurrency security services, likely exploiting user trust in wallet protection tools. No explicit drainer kit signatures have been confirmed, but the domain exhibits behavioral patterns consistent with wallet-focused phishing campaigns, including simulated transaction prompts and seed phrase collection forms. Infrastructure analysis reveals the domain resolves to IP address 64.29.17.131, hosted on infrastructure belonging to AS16509 (Amazon.com, Inc.) in the United States. The domain was registered through Vercel Inc. on March 13, 2026, an unusually forward-dated creation timestamp that may indicate automated or bulk registration practices. Detection metrics show 1 of 95 security vendors on VirusTotal flagging the domain, while three independent blocklists—PhishDestroy, MetaMask, and SEAL—have classified it as malicious. The SSL certificate is issued by Google Trust Services (WR1), providing HTTPS encryption that enhances the appearance of legitimacy. As of the latest verification, safelock-web.vercel.app remains active and accessible. No takedown actions have been observed, and the domain continues to resolve without interruption. The low detection rate on aggregate scanning platforms suggests either evasion techniques or recent deployment, reducing visibility among automated security tools. Users are advised to block the domain at the network level, avoid interaction with any linked resources, and verify wallet addresses through trusted channels. Organizations should update internal blocklists with the domain and associated IP to mitigate exposure.
Erkenntnisse zur Netzwerksicherheit
Pipeline zur Reaktion auf Sicherheitsbedrohungen
Status der öffentlichen Sperrliste
Technologien · 2 identified
Cloud platform for frontend deployment, optimized for Next.js.
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
VirusTotal-Analyse
Website-Performanceanalyse
Google PageSpeed Insights — mobile performance audit of safelock-web.vercel.app · checked Mar 13, 2026
Nachweise und externe Berichte
Wurden Sie von dieser Website betroffen?
Wenn Sie Kontoanmeldeinformationen, persönliche oder Zahlungsinformationen eingegeben oder eine Datei von dieser Domain heruntergeladen haben, ergreifen Sie sofort Maßnahmen. Nachfolgend finden Sie Ressourcen, die Ihnen helfen, den Vorfall zu melden und sich zu schützen.
Melden Sie sich bei Ihren örtlichen Behörden
Wählen Sie Ihr Land aus, um Offizielle Kontakte im Bereich Cyberkriminalität oder einen Beschwerdeentwurf erstellen → zu erhalten.
Jede beliebige Domain prüfen
Bedrohungsanalyse anhand gespeicherter Blocklisten, WHOIS, DNS und öffentlicher Scan-Beweise
Jetzt scannenPhishing melden
Melden Sie verdächtige Domains an unsere Bedrohungsdatenbank – schützen Sie die Community
MeldenEchtzeit-Bedrohungsfeed
Aktuelle Phishing-Meldungen und beobachtete Verfügbarkeitsänderungen
ÜberwachenBleiben Sie auf dem Laufenden, bleiben Sie sicher
Beobachten Sie aktuelle Bedrohungen oder legen Sie Widerspruch gegen diesen Eintrag ein, wenn Sie der Meinung sind, dass es sich um einen Fehlalarm handelt