walle-pi[.]vercel[.]app
“PayPal”
walle-pi.vercel.app — Inhalt nicht verfügbar. Markenidentität: PayPal; Betrugstyp: E Commerce Scam. Zusammenfassung der Beweislage: VirusTotal 20/95 (ADMINUSLabs, Criminal IP, alphaMountain.ai, BitDefender, CyRadar); CF Radar malicious; PhishDestroy score 95/100. Registrar: Tucows.
Die ausführliche Analyse von PhishDestroy AI bleibt auf Englisch, damit der ursprüngliche forensische Bericht unverändert bleibt.
The domain walle-pi.vercel.app was registered on February 21, 2026 through Tucows Domains Inc. and is currently taken offline. DNS resolution points to the IP address 64.29.17.67, which belongs to Amazon.com, Inc. (AS16509) and is geolocated in the United States. The domain is served via Vercel infrastructure, as indicated by the nameservers ns1.vercel-dns-3.com through ns4.vercel-dns-3.com and the presence of Vercel in the technology fingerprint. TLS termination uses a certificate issued by Google Trust Services under the WR1 intermediate, providing standard HTTPS encryption and HSTS enforcement. An HTTP 451 status code is returned, indicating that the resource is unavailable for legal reasons, consistent with the reported offline status.
Security scanning on VirusTotal shows that 20 of 95 antivirus and URL‑reputation engines flagged the domain, reflecting a moderate level of detection across independent vendors. The domain is listed on one public security blocklist and has been blocked by the PhishDestroy mitigation service. The page title reported by the scanner is "PayPal," and the threat intelligence tags the site as an e‑commerce scam that impersonates PayPal. The underlying malicious payload is associated with an "Airdrop Scam" kit, suggesting that the operator may have reused a known phishing framework.
Observations confirm that the domain leverages legitimate cloud services (Vercel, Google TLS) to host a counterfeit PayPal‑related page, a common tactic to increase perceived trustworthiness. While the site is offline, the infrastructure components—registrar, hosting ASN, and TLS provider—remain reusable for future campaigns. Defenders should continue to monitor the IP address 64.29.17.67 for any re‑activation, enforce blocklist updates for the domain and its associated IP, and consider adding the domain to corporate URL filtering policies.
Erkenntnisse zur Netzwerksicherheit
Pipeline zur Reaktion auf Sicherheitsbedrohungen
Status der öffentlichen Sperrliste
Technologien · 2 identified
Vercel is a cloud platform for static frontends and serverless functions.
vercel.com 100 % KonfidenzHTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 100 % KonfidenzVirusTotal-Analyse
Archivierte Beweise
Nachweise und externe Berichte
Wurden Sie von dieser Website betroffen?
Wenn Sie Kontoanmeldeinformationen, persönliche oder Zahlungsinformationen eingegeben oder eine Datei von dieser Domain heruntergeladen haben, ergreifen Sie sofort Maßnahmen. Nachfolgend finden Sie Ressourcen, die Ihnen helfen, den Vorfall zu melden und sich zu schützen.
Melden Sie sich bei Ihren örtlichen Behörden
Wählen Sie Ihr Land aus, um Offizielle Kontakte im Bereich Cyberkriminalität oder einen Beschwerdeentwurf erstellen → zu erhalten.
Jede beliebige Domain prüfen
Bedrohungsanalyse anhand gespeicherter Blocklisten, WHOIS, DNS und öffentlicher Scan-Beweise
Jetzt scannenPhishing melden
Melden Sie verdächtige Domains an unsere Bedrohungsdatenbank – schützen Sie die Community
MeldenEchtzeit-Bedrohungsfeed
Aktuelle Phishing-Meldungen und beobachtete Verfügbarkeitsänderungen
ÜberwachenBleiben Sie auf dem Laufenden, bleiben Sie sicher
Beobachten Sie aktuelle Bedrohungen oder legen Sie Widerspruch gegen diesen Eintrag ein, wenn Sie der Meinung sind, dass es sich um einen Fehlalarm handelt