facebookform[.]vercel[.]app
“Testing Forms”
facebookform.vercel.app — Ammantato · raggiungibile (HTTP 451). Simulazione del marchio: Facebook; Tipo di truffa: Social Media Phishing. Riepilogo delle prove: VirusTotal 20/91 (ADMINUSLabs, Criminal IP, alphaMountain.ai, BitDefender, CyRadar); URLQuery 3 alerts; URLScan malicious verdict; CF Radar malicious; cloaking observed; PhishDestroy score 100/100. Registrar: Vercel.
L’analisi dettagliata di PhishDestroy AI resta in inglese per preservare il rapporto forense originale.
This domain facebookform.vercel.app is assessed as a high-risk brand impersonation phishing endpoint targeting Facebook users. Analysis indicates it is designed to mimic Facebook-related form workflows, likely to trick users into submitting login credentials or sensitive account information. The observed page title 'Testing Forms' suggests a decoy interface commonly used in phishing kits to simulate legitimate form testing environments while masking credential capture functionality. The domain is currently active and continues to present exposure risk.
Evidence supports malicious classification across multiple telemetry sources. VirusTotal reports 16/95 security vendors flagging the domain as malicious. The domain is registered through Vercel Inc. and resolves to IP 64.29.17.131 hosted in the United States under Vercel infrastructure. It appears on 1 security blocklist and is protected by SSL issued by Google Trust Services / WR1. The domain specifically impersonates Facebook, increasing the likelihood of user trust exploitation and credential harvesting attempts.
The domain remains active, indicating ongoing risk of user exposure. Users who interacted with this site should assume potential credential compromise, especially if Facebook credentials were entered. Immediate mitigation includes password reset, session invalidation across devices, and enabling multi-factor authentication. Any reused credentials should be changed across all services. Security teams should monitor for unauthorized login attempts and block the domain at network and DNS layers. Endpoint checks should be performed to ensure no token theft or browser-based persistence mechanisms are present.
Informazioni sulla sicurezza di rete
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| OpenDNS | facebookform.vercel.app |
phishing | Phishing Block |
| Cloudflare DNS | facebookform.vercel.app |
malicious | Sinkholed |
| DNS4EU | facebookform.vercel.app |
malicious | Sinkholed |
Pipeline di risposta alle minacce
Stato della lista di blocco pubblica
Informazioni forensi
Tecnologie · 2 identified
Cloud platform for frontend deployment, optimized for Next.js.
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Analisi di VirusTotal
Dati e relazioni esterne
Questo sito ti ha influenzato in qualche modo?
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.
Verifica qualsiasi dominio
Analisi delle minacce utilizzando blocklist archiviate, WHOIS, DNS e prove di scansione pubblica
Scansiona oraSegnala un tentativo di phishing
Segnala i domini sospetti al nostro database delle minacce — proteggi la comunità
SegnalaFeed in tempo reale sulle minacce
Segnalazioni recenti di phishing e modifiche osservate della disponibilità
MonitoraRimani informato, rimani al sicuro
Controlla le minacce in tempo reale oppure contesta questa segnalazione se ritieni che si tratti di un falso positivo