instagram-auth[.]vercel[.]app
“Instagram”
Сводка доказательств
This domain, instagram-auth.vercel.app, poses a high-risk credential phishing threat targeting users of a popular social media platform. The site is designed to replicate the login interface of Instagram, tricking visitors into entering their account credentials. Once submitted, these credentials are captured by threat actors for unauthorized access, account takeover, or further malicious activities such as spam distribution or financial fraud. The domain specifically exploits trust in the platform's branding to deceive users into disclosing sensitive information. Analysis indicates that instagram-auth.vercel.app is flagged by 17 out of 95 security vendors on VirusTotal, confirming its malicious intent. Infrastructure analysis reveals the domain was registered through Vercel Inc. and resolves to the IP address 216.198.79.3, hosted on Amazon.com, Inc. infrastructure (AS16509). The SSL certificate is issued by Google Trust Services, which, while legitimate, is commonly abused in phishing campaigns to create a false sense of security. The domain appears on two security blocklists, including PhishDestroy and PhishingDB, and is classified as phishing by Google Safe Browsing. The page title explicitly mimics the targeted platform, further supporting its deceptive purpose. If you or someone in your network visited instagram-auth.vercel.app and entered login credentials, immediate action is required. First, change the password for the affected account and any other platforms where the same credentials may have been reused. Enable multi-factor authentication if not already active. Monitor the account for unauthorized activity, such as unfamiliar posts, messages, or changes to profile settings. If financial or personal data was entered, consider placing a fraud alert on credit reports and reviewing bank statements for suspicious transactions. Report the incident to the platform's official support channels to aid in mitigating further abuse. Finally, ensure endpoint security tools are updated to block known malicious domains and IPs associated with this campaign.
Data Coverage
Данные сетевой безопасности
Процесс реагирования на угрозы
Проверка по блок-листам
10 внешних источников под наблюдением · снимок от 11.08.2026
10 внешних источников под наблюдением Совпадений нет
Хронология обнаружения
-
Статус домена
Доступен → Недоступен
-
Cloudflare Radar
Сканирование Cloudflare Radar сохранено · Открыть сканирование
Анализ VirusTotal
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание