0authxfinity.vercel.app
“Deployment Unavailable”
Evidence Summary
This domain, 0authxfinity.vercel.app, is identified as a high-severity phishing resource targeting users through fraudulent OAuth or identity verification interfaces. Analysis indicates the domain impersonates legitimate authentication flows, likely to harvest credentials or session tokens from unsuspecting victims. The inclusion of "xfinity" in the subdomain suggests an attempt to exploit trust in a major telecommunications provider, while the use of a platform-as-a-service hosting provider obscures infrastructure ownership and complicates takedown efforts. Infrastructure analysis reveals the domain resolves to the IP address 64.29.17.131, hosted within autonomous system AS16509, operated by a major cloud provider in the United States. The domain is registered through Vercel Inc., a platform commonly used for rapid deployment of web applications, which may have facilitated its swift activation and subsequent abuse. Detection metrics show 21 out of 95 security vendors on a multi-engine scanning platform flagged the domain as malicious, while Google Safe Browsing has explicitly classified it as phishing. The domain appears on two independent security blocklists, including specialized phishing repositories, confirming its malicious intent. As of the latest assessment, 0authxfinity.vercel.app has been taken offline, likely following abuse reports or automated enforcement actions by the hosting provider. While the immediate threat has been mitigated, residual risk persists due to potential reuse of collected credentials or reactivation under similar domains. Users who may have interacted with the site are advised to invalidate any entered credentials, enable multi-factor authentication on sensitive accounts, and monitor for unauthorized access. Organizations should update detection rules to include the observed indicators, including the IP address and SSL certificate issuer, to prevent future exposure.
Security Signals
Network Security Intelligence
Detection timeline
-
Domain status
Reachable → Unreachable
-
Cloudflare Radar
Cloudflare Radar scan stored · Open scan
-
Domain status
Reachable → Unreachable
Threat Response Pipeline
Public Blocklist Status
Blocklist coverage
11 monitored external feeds · stored snapshot Sep 10, 2026
Technologies · 2 identified
Cloud platform for frontend deployment, optimized for Next.js.
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
VirusTotal Analysis
Archived Evidence
Technologies
2 high-confidence technologies identified
Evidence & External Reports
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive