rpcautoresolve[.]vercel[.]app
“Deployment Unavailable”
rpcautoresolve.vercel.app — Conteúdo indisponível. Tipo de golpe: Crypto Scam. Resumo das evidências: VirusTotal 10/93 (CRDF, CyRadar, Ermes, ESET, Fortinet); URLQuery 1 alert; 1 external blocklist match (ScamSniffer); PhishDestroy score 80/100. Registrador: Tucows.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
The domain rpcautoresolve.vercel.app was created on February 21, 2026 through Tucows Domains Inc. and resolves to the IP address 64.29.17.67, which is owned by Amazon.com, Inc. (AS16509) in the United States. The site hosted on Vercel presented the HTTP status code 451 and the page title "Deployment Unavailable," indicating that the content was taken offline, likely in response to abuse reports. TLS termination is provided by a Google Trust Services certificate (WR1), confirming the use of a legitimate certificate authority but not mitigating the underlying malicious intent.
VirusTotal analysis recorded 10 detections out of 93 security vendors, and the domain is listed on two independent blocklists, specifically PhishDestroy and ScamSniffer. The technology fingerprint includes Vercel and HSTS, and the observed scam type is classified as a crypto scam. While the site is currently offline, the infrastructure details demonstrate a typical abuse pattern where a legitimate hosting platform is leveraged for phishing or credential harvesting.
The precise payload, lure content, or target audience remains unconfirmed due to the absence of live page evidence. Defenders should continue to block the domain at network perimeter assets, monitor the associated IP address for any future re‑use, and incorporate the domain into threat intelligence feeds. Ongoing surveillance of the registrar and hosting provider for similar patterns is advised, as well as periodic re‑scanning to capture any re‑appearance of malicious content.
Inteligência de segurança de rede
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Quad9 DNS | openaiwalletsyn.com |
malicious | Sinkholed |
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Tecnologias · 2 identified
Cloud platform for frontend deployment, optimized for Next.js.
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Análise do VirusTotal
Evidências e relatórios externos
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo