186tyesy[.]vercel[.]app
“Poczta - Najlepsza Poczta, największe załączniki - WP”
186tyesy.vercel.app — Encoberto · alcançável (HTTP 404). Tipo de golpe: Brand Impersonation. Resumo das evidências: VirusTotal 14/91 (BitDefender, CyRadar, ESET, Emsisoft, Fortinet); cloaking observed; PhishDestroy score 92/100. Registrador: Vercel.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
This domain, 186tyesy.vercel.app, is currently engaged in a high-risk phishing campaign impersonating the WP webmail service, specifically targeting Polish-speaking users. Analysis indicates the threat type as brand impersonation phishing, designed to harvest login credentials by mimicking the legitimate WP Poczta interface. The page title, "Poczta - Najlepsza Poczta, największe załączniki - WP," directly replicates the branding of the authentic WP webmail portal, increasing the likelihood of successful deception. As of the latest verification, the domain remains active and operational, posing an ongoing risk to unsuspecting users. Infrastructure analysis reveals the domain is registered through Vercel Inc., a platform commonly exploited for rapid deployment of phishing pages due to its ease of use and free hosting capabilities. The domain resolves to the IP address 216.198.79.195, which has been flagged by 13 of 95 security vendors on VirusTotal for malicious activity. No additional historical registration data or creation date is publicly available, limiting temporal attribution. However, the detection ratio of 13/95 indicates moderate to high confidence in malicious classification among security vendors. The absence of widespread blocklisting suggests the campaign may still be in an early or targeted phase, evading broader detection mechanisms. Current assessment confirms the domain remains active and continues to host the fraudulent WP-themed phishing page. Organizations and end-users are advised to implement immediate mitigations, including blocking the domain and IP at network perimeters, deploying endpoint protection rules to detect and prevent access, and conducting user awareness training to recognize brand impersonation tactics. Given the high-risk nature of credential theft, affected users should be instructed to reset passwords for any accounts accessed via the fraudulent portal. Continuous monitoring of related infrastructure is recommended, as threat actors frequently rotate domains and IPs to sustain campaign effectiveness.
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Análise do VirusTotal
Evidências e relatórios externos
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo