# PhishDestroy threat dossier — peacepaymentsettlementsinvs.vercel.app ================================================================ Fetched: 2026-07-22 07:30:28 UTC Canonical: https://phishdestroy.io/domain/peacepaymentsettlementsinvs.vercel.app/ ## VERDICT ---------------------------------------------------------------- TAKEN DOWN (neutralised) Composite threat score: 78/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 0/91 security vendors flagged this domain Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 216.198.79.3 (US, Atlanta) ASN: AS16509 Amazon.com, Inc. Hosting org: Lefkoff Industries Registrar: Vercel HTTP response: 451 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Google Trust Services / WR1 Expires: 2026-09-26 Status: INVALID chain Fingerprint: ee54cb11f16cc311b3acbae57f8fbb03f338c1b2a20de72722c3eafd0dae0140 ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: CLOSED — no report required. This domain was neutralised before the abuse-report cycle could be dispatched — either the hosting provider / registrar suspended it on their own, the DNS went dead, or the operator abandoned the infrastructure. PhishDestroy keeps the evidence bundle on file for audit but no formal notice was sent. ## TIMELINE ---------------------------------------------------------------- First detected: 2026-07-19 12:38:36 UTC (by PhishDestroy tracker) Last verified: 2026-07-22 08:20:23 UTC Neutralised: 2026-07-20 00:23:12 UTC Current status: taken down (registrar suspended or DNS dead) ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-19 12:53:41 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] peacepaymentsettlementsinvs.vercel.app — Phishing Report peacepaymentsettlementsinvs.vercel.app is currently listed as an active generic phishing infrastructure. The domain resolves to the IP address 216.198.79.3 and returns an HTTP 308 redirect response, indicating that the server is reachable and likely forwarding traffic to another location. Registration details show the domain was provisioned through Vercel, a cloud platform that frequently hosts short‑lived malicious sites. The domain has been blocked by the PhishDestroy sinkhole and appears on a single external blocklist, confirming that at least one defensive feed has identified it as malicious. VirusTotal analysis of the domain has been performed by 91 scanning engines, none of which flagged it at the time of the scan; this absence of detections does not imply safety and should be interpreted as inconclusive. Evidence does not reveal the specific landing page content, targeted brand, or phishing kit employed, so the exact lure remains unknown. The presence of a 308 status suggests the site may be employing URL redirection to obscure its final payload. Because the domain is hosted on Vercel, the underlying infrastructure can be rapidly regenerated, making takedown efforts potentially short‑lived. Defenders should add both the domain name and its resolved IP address to network deny lists, monitor outbound connections for HTTP 308 redirects to unknown hosts, and consider enforcing stricter outbound filtering for any traffic destined to Vercel‑hosted subdomains that are not explicitly authorized. Continuous re‑scanning of the domain and its IP is recommended, as the threat actor may modify the payload or host new phishing pages without changing the underlying host. The case remains under investigation, and further forensic analysis of the redirected target is required to fully characterize the phishing campaign. ## EVIDENCE HASHES ---------------------------------------------------------------- TLS cert SHA-256: ee54cb11f16cc311b3acbae57f8fbb03f338c1b2a20de72722c3eafd0dae0140 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/peacepaymentsettlementsinvs.vercel.app/ JSON API: https://api.destroy.tools/v1/check?domain=peacepaymentsettlementsinvs.vercel.app Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 187,759 domains (57,336 alive under monitoring, 128,779 confirmed takedowns/dead). Site: https://phishdestroy.io