mainnettdappfix[.]vercel[.]app
“Wallet Rectify - Rectification, Synchronization, and Validation”
mainnettdappfix.vercel.app — Conteúdo indisponível. Representação da marca: Across; Tipo de golpe: Investment Scam. Resumo das evidências: VirusTotal 5/93 (alphaMountain.ai, CyRadar, Fortinet, G-Data, Webroot); 4 external blocklist matches; PhishDestroy score 82/100. Registrador: Tucows.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
Analysis of the domain mainnettdappfix.vercel.app indicates it was actively used in an investment scam campaign targeting cryptocurrency wallet users. The domain, registered on February 21, 2026, through Tucows Domains Inc., resolved to the IP address 64.29.17.3, hosted under Amazon.com, Inc. (AS16509) in the United States. The page title, 'Wallet Rectify - Rectification, Synchronization, and Validation,' suggests an attempt to deceive users into believing the site offers legitimate wallet recovery or synchronization services, a common tactic in cryptocurrency-related fraud. As of July 22, 2026, the domain has been taken offline, returning an HTTP 451 status, which typically indicates content unavailable for legal reasons. Prior to its removal, the domain appeared on five security blocklists and was actively blocked by multiple security vendors, including PhishDestroy, ScamSniffer, Polkadot, Enkrypt, and Codeesura.
The SSL certificate, issued by Google Trust Services (WR1), does not mitigate the domain's malicious classification, as phishing sites frequently employ valid certificates to appear legitimate. Detection metrics from VirusTotal, where five out of ninety-three security vendors flagged the domain, further corroborate its malicious nature. The domain was hosted on Vercel, a platform often abused for rapid deployment of phishing infrastructure due to its ease of use and free tier. The presence of HTTP Strict Transport Security (HSTS) headers indicates an attempt to reinforce the illusion of security, though this does not offset the domain's fraudulent intent.
Defenders should treat this domain as part of a broader pattern of investment scams leveraging Vercel-hosted subdomains. Network-level blocking of the resolved IP (64.29.17.3) and monitoring for similar subdomains under vercel.app are recommended.
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Tecnologias · 2 identified
Cloud platform for frontend deployment, optimized for Next.js.
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Análise do VirusTotal
Evidências e relatórios externos
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo