cratdappclaim[.]vercel[.]app
“CratD2C”
Riepilogo delle prove
The domain cratdappclaim.vercel.app was registered on February 21, 2026 through Tucows Domains Inc. and is hosted on the Vercel platform, as indicated by the detected Vercel technology fingerprint and the presence of HTTP Strict Transport Security (HSTS). The site presented an HTTP 451 response and the page title “CratD2C” before being taken offline. The TLS certificate was issued by Google Trust Services under the WR1 profile, confirming a valid HTTPS endpoint at the time of capture. Network resolution points to the IPv4 address 64.29.17.131, which belongs to Amazon.com, Inc. (AS16509) and resolves to a location in the United States. VirusTotal recorded a single positive detection out of 95 scanning engines, and the domain appears on four independent security blocklists, including PhishDestroy, Polkadot, Enkrypt, and Codeesura.
The combined evidence aligns with the classification of a crypto‑drainer scam, a subset of crypto‑related fraud that typically attempts to exfiltrate digital assets from unsuspecting victims. No additional artifacts such as login forms, redirects, or payloads have been observed because the site is currently offline. Consequently, the precise mechanisms used to lure victims or to interact with cryptocurrency wallets remain unknown. Likewise, the presence of any malicious scripts or third‑party services could not be verified.
Defenders should continue to block the domain at network perimeter and DNS layers, monitor for any resurgence of the same IP address or Vercel sub‑domain patterns, and add the associated IP to internal deny lists. Given the legitimate‑looking SSL certificate, reliance on certificate validation alone is insufficient; threat‑intel feeds that incorporate the observed blocklist entries and the VirusTotal detection should be consulted for early warning. Analysts should also watch for newly registered Vercel‑hosted domains that reuse the “CratD” naming convention, as they may represent follow‑on infrastructure.
Data Coverage
Pipeline di risposta alle minacce
Copertura delle blocklist
10 fonti esterne monitorate · snapshot del 12/08/2026
Cronologia del rilevamento
-
Stato del dominio
Raggiungibile → Non raggiungibile
-
Cloudflare Radar
Scansione Cloudflare Radar archiviata · Apri scansione
-
Cloudflare Radar
Scansione Cloudflare Radar archiviata · Apri scansione
Analisi di VirusTotal
Questo sito ti ha influenzato in qualche modo?
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.
Verifica qualsiasi dominio
Analisi delle minacce utilizzando blocklist archiviate, WHOIS, DNS e prove di scansione pubblica
Scansiona oraSegnala un tentativo di phishing
Segnala i domini sospetti al nostro database delle minacce — proteggi la comunità
SegnalaFeed in tempo reale sulle minacce
Segnalazioni recenti di phishing e modifiche osservate della disponibilità
MonitoraRimani informato, rimani al sicuro
Controlla le minacce in tempo reale oppure contesta questa segnalazione se ritieni che si tratti di un falso positivo