# PhishDestroy threat dossier — reimagined-funicular-ivory.vercel.app ================================================================ Fetched: 2026-05-12 15:12:57 UTC Canonical: https://phishdestroy.io/domain/reimagined-funicular-ivory.vercel.app/ ## VERDICT ---------------------------------------------------------------- ACTIVE + CLOAKED — returns HTTP 666 to scanners, real fraudulent site to victims Composite threat score: 92/100 (PhishDestroy scoring — see methodology below) Cloaking: DETECTED — domain returns custom HTTP 666 to scanners while serving fraudulent content to real users (type: content_split) (score: 1/6) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 16/95 security vendors flagged this domain Flagging vendors: ADMINUSLabs, alphaMountain.ai, BitDefender, CyRadar, ESET, Emsisoft, Fortinet, G-Data, Google Safebrowsing, Kaspersky, LevelBlue, Lionic, Netcraft, Sophos, VIPRE, Webroot Google Safe Browsing: FLAGGED ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 64.29.17.131 (US, Walnut) ASN: AS16509 Amazon.com, Inc. Hosting org: Vercel, Inc Registrar: Vercel Inc. Nameservers: NS_NOT_FOUND Registered: 2026-05-12 Page title: Naver Sign in HTTP response: 200 ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-05-12 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-05-12 15:47:56 UTC (by PhishDestroy tracker) Last verified: 2026-05-12 17:25:35 UTC Current status: ACTIVE — cloaked behind HTTP 666 to evade scanners ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019e1c38-f9fc-7219-9045-9ec4db90ed79/ Wayback Machine: https://web.archive.org/web/*/reimagined-funicular-ivory.vercel.app crt.sh CT logs: https://crt.sh/?q=%25.reimagined-funicular-ivory.vercel.app Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=reimagined-funicular-ivory.vercel.app AlienVault OTX: https://otx.alienvault.com/indicator/domain/reimagined-funicular-ivory.vercel.app URLhaus: https://urlhaus.abuse.ch/host/reimagined-funicular-ivory.vercel.app/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-05-12 15:49:37 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] The domain reimagined-funicular-ivory.vercel.app poses a high risk as a crypto drainer phishing site. This threat type involves malicious actors masquerading as legitimate cryptocurrency services to trick users into connecting wallets and authorizing unauthorized transactions, often draining digital assets without consent. PhishDestroy identifies this domain as actively malicious, with multiple indicators confirming its phishing nature. VirusTotal analysis reveals 16 out of 95 security vendors flag this domain, indicating a high false-negative risk. The domain is registered through Vercel Inc. and resolves to IP 64.29.17.131. Google Safe Browsing categorizes it under SOCIAL_ENGINEERING, a classification reserved for deceptive sites designed to trick users into revealing sensitive information or performing harmful actions. The domain operates under a Google Trust Services SSL certificate, which may lull users into a false sense of security by displaying a green padlock. Despite this, the site’s malicious intent is further corroborated by its presence on multiple blocklists targeting phishing and fraudulent activities. The combination of these factors—high-risk categorization, poor detection rates, and technical infrastructure aligned with legitimate services—solidifies its status as a credible and immediate threat to cryptocurrency users. Users should avoid interacting with this domain entirely, particularly if it prompts wallet connections or login attempts. To mitigate risks, verify the legitimacy of any cryptocurrency-related website through PhishDestroy’s threat intelligence database before proceeding with transactions or data entry. Enable wallet address verification features if available, and never authorize transactions from unfamiliar or unverified domains. Additionally, revoke any unintended smart contract approvals via blockchain explorers like Etherscan or Polygonscan if this domain has already been accessed. Always cross-reference URLs with official project websites and use bookmarks for frequently visited services to prevent typosquatting attacks. Exercise heightened caution with domains hosted on reputable platforms like Vercel, as threat actors often exploit legitimate infrastructure to host malicious content due to its trusted status. ## EVIDENCE HASHES ---------------------------------------------------------------- Favicon MD5: b707378e4db3fcca990f228c4d865f86 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (volunteer takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/reimagined-funicular-ivory.vercel.app/ JSON API: https://api.destroy.tools/v1/check?domain=reimagined-funicular-ivory.vercel.app Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: volunteer-driven open-source threat-intelligence platform. Tracked: 148,513 domains (37,014 alive under monitoring, 111,191 confirmed takedowns/dead). Site: https://phishdestroy.io