amazon-using-nextjs-1o67[.]vercel[.]app
“Amazon”
Evidence Summary
Analysis of the domain amazon-using-nextjs-1o67.vercel.app indicates an active phishing infrastructure targeting user credentials, classified as elevated risk. The domain is hosted on Vercel's platform, a common choice for rapid deployment of phishing pages due to its free tier and ease of use. As of August 02, 2026, eighteen of ninety-one security vendors on VirusTotal have flagged this domain, signaling detection by a significant portion of the threat intelligence community. The domain also appears on at least one security blocklist and is actively blocked by PhishDestroy, further corroborating its malicious nature. Infrastructure analysis reveals the domain is configured with a valid SSL certificate, which is frequently exploited by threat actors to lend a false sense of legitimacy to phishing pages.
The use of 'amazon' in the subdomain suggests an attempt to impersonate Amazon services, though the exact content and targeting of the phishing page remain unconfirmed as no brand-specific indicators or page titles were provided. The deployment of Next.js, a React framework, aligns with observed trends where phishing kits leverage modern web technologies to evade detection and enhance user interaction. Defenders should treat this domain as hostile. Network-level blocking is recommended, particularly for organizations with Amazon-affiliated services or users likely to encounter credential harvesting attempts.
Security teams should monitor for connections to this domain in logs and investigate any associated endpoints or IP addresses. Given the domain's presence on multiple detection platforms, additional blocklist inclusions are likely imminent. No registrar or hosting anomalies were provided, but the use of Vercel's infrastructure is consistent with low-cost, high-velocity phishing campaigns. Further analysis of the page content and payload delivery mechanisms is advised to determine the full scope of the threat.
Data Coverage
Network Security Intelligence
Threat Response Pipeline
Blocklist coverage
10 monitored external feeds · stored snapshot Aug 12, 2026
10 monitored external feeds No match
Technologies
6 high-confidence technologies identified
VirusTotal Analysis
Archived Evidence
Site Performance Analysis
Google PageSpeed Insights — mobile performance audit of amazon-using-nextjs-1o67.vercel.app · checked Aug 2, 2026
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive