cratdappclaim[.]vercel[.]app
“CratD2C”
cratdappclaim.vercel.app — Conteúdo indisponível. Tipo de golpe: Crypto Scam. Resumo das evidências: VirusTotal 1/95 (Trustwave); 3 external blocklist matches (Polkadot, Enkrypt, Codeesura); PhishDestroy score 74/100. Registrador: Tucows.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
The domain cratdappclaim.vercel.app was registered on February 21, 2026 through Tucows Domains Inc. and is hosted on the Vercel platform, as indicated by the detected Vercel technology fingerprint and the presence of HTTP Strict Transport Security (HSTS). The site presented an HTTP 451 response and the page title “CratD2C” before being taken offline. The TLS certificate was issued by Google Trust Services under the WR1 profile, confirming a valid HTTPS endpoint at the time of capture. Network resolution points to the IPv4 address 64.29.17.131, which belongs to Amazon.com, Inc. (AS16509) and resolves to a location in the United States. VirusTotal recorded a single positive detection out of 95 scanning engines, and the domain appears on four independent security blocklists, including PhishDestroy, Polkadot, Enkrypt, and Codeesura.
The combined evidence aligns with the classification of a crypto‑drainer scam, a subset of crypto‑related fraud that typically attempts to exfiltrate digital assets from unsuspecting victims. No additional artifacts such as login forms, redirects, or payloads have been observed because the site is currently offline. Consequently, the precise mechanisms used to lure victims or to interact with cryptocurrency wallets remain unknown. Likewise, the presence of any malicious scripts or third‑party services could not be verified.
Defenders should continue to block the domain at network perimeter and DNS layers, monitor for any resurgence of the same IP address or Vercel sub‑domain patterns, and add the associated IP to internal deny lists. Given the legitimate‑looking SSL certificate, reliance on certificate validation alone is insufficient; threat‑intel feeds that incorporate the observed blocklist entries and the VirusTotal detection should be consulted for early warning. Analysts should also watch for newly registered Vercel‑hosted domains that reuse the “CratD” naming convention, as they may represent follow‑on infrastructure.
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Tecnologias · 2 identified
Cloud platform for frontend deployment, optimized for Next.js.
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Análise do VirusTotal
Evidências e relatórios externos
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo