186tyesy[.]vercel[.]app
“Poczta - Najlepsza Poczta, największe załączniki - WP”
186tyesy.vercel.app — ढका हुआ · पहुंच योग्य (HTTP 404). घोटाले का प्रकार: Brand Impersonation. साक्ष्य सारांश: VirusTotal 14/91 (BitDefender, CyRadar, ESET, Emsisoft, Fortinet); cloaking observed; PhishDestroy score 92/100. रजिस्ट्रार: Vercel.
मूल फॉरेंसिक रिकॉर्ड सुरक्षित रखने के लिए नीचे का विस्तृत PhishDestroy AI विश्लेषण अंग्रेज़ी में रखा गया है।
This domain, 186tyesy.vercel.app, is currently engaged in a high-risk phishing campaign impersonating the WP webmail service, specifically targeting Polish-speaking users. Analysis indicates the threat type as brand impersonation phishing, designed to harvest login credentials by mimicking the legitimate WP Poczta interface. The page title, "Poczta - Najlepsza Poczta, największe załączniki - WP," directly replicates the branding of the authentic WP webmail portal, increasing the likelihood of successful deception. As of the latest verification, the domain remains active and operational, posing an ongoing risk to unsuspecting users. Infrastructure analysis reveals the domain is registered through Vercel Inc., a platform commonly exploited for rapid deployment of phishing pages due to its ease of use and free hosting capabilities. The domain resolves to the IP address 216.198.79.195, which has been flagged by 13 of 95 security vendors on VirusTotal for malicious activity. No additional historical registration data or creation date is publicly available, limiting temporal attribution. However, the detection ratio of 13/95 indicates moderate to high confidence in malicious classification among security vendors. The absence of widespread blocklisting suggests the campaign may still be in an early or targeted phase, evading broader detection mechanisms. Current assessment confirms the domain remains active and continues to host the fraudulent WP-themed phishing page. Organizations and end-users are advised to implement immediate mitigations, including blocking the domain and IP at network perimeters, deploying endpoint protection rules to detect and prevent access, and conducting user awareness training to recognize brand impersonation tactics. Given the high-risk nature of credential theft, affected users should be instructed to reset passwords for any accounts accessed via the fraudulent portal. Continuous monitoring of related infrastructure is recommended, as threat actors frequently rotate domains and IPs to sustain campaign effectiveness.
धमकी प्रतिक्रिया पाइपलाइन
सार्वजनिक ब्लॉकलिस्ट स्थिति
वायरसटोटल विश्लेषण
साक्ष्य और बाहरी रिपोर्टें
क्या आप इस साइट से प्रभावित हुए?
यदि आपने खाता क्रेडेंशियल, व्यक्तिगत या भुगतान जानकारी दर्ज की है, या इस डोमेन से कोई फ़ाइल डाउनलोड की है, तो तुरंत कार्रवाई करें। घटना की रिपोर्ट करने और अपनी सुरक्षा करने में आपकी सहायता के लिए नीचे संसाधन दिए गए हैं।
अपने स्थानीय अधिकारियों को रिपोर्ट करें
आधिकारिक साइबर अपराध संपर्क, या एक शिकायत ड्राफ्ट बनाएं → प्राप्त करने के लिए अपना देश चुनें।
किसी भी डोमेन की जाँच करें
संग्रहीत ब्लॉकलिस्ट, WHOIS, DNS और सार्वजनिक स्कैन साक्ष्य का उपयोग करके खतरे का विश्लेषण
अभी स्कैन करेंफ़िशिंग की रिपोर्ट करें
संदिग्ध डोमेन हमारे थ्रेट डेटाबेस में जमा करें — समुदाय की सुरक्षा करें
रिपोर्ट करेंसीधा खतरा फीड
हाल की फ़िशिंग रिपोर्टें और उपलब्धता में परिवर्तन देखे गए
निगरानी करेंजानकारी में रहें, सुरक्षित रहें
लाइव खतरों की निगरानी करें या यदि आपको लगता है कि यह एक गलत सकारात्मक है तो इस लिस्टिंग को चुनौती दें।