jiks-tau[.]vercel[.]app
“Bell Business Site”
jiks-tau.vercel.app — Контент недоступен. Сводка доказательств: VirusTotal 18/93 (ADMINUSLabs, Criminal IP, alphaMountain.ai, BitDefender, CyRadar); PhishDestroy score 95/100. Регистратор: Tucows.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
Analysis indicates that jiks-tau.vercel.app was associated with a fake login phishing operation. The observed page title, "Bell Business Site," suggests potential brand impersonation intended to collect user credentials through deceptive authentication workflows. No evidence of a drainer kit was identified in the available intelligence. The domain was categorized as generic_phishing and exhibited characteristics commonly associated with credential-harvesting infrastructure.
Technical indicators show a VirusTotal detection rate of 18/95 security vendors. Registration records indicate the domain was registered through Tucows Domains Inc. and created on February 21, 2026. Infrastructure analysis identified resolution to IP address 216.198.79.3, geolocated in the United States under AS16509 Amazon.com, Inc. The site presented an SSL certificate issued by Google Trust Services / WR1. The domain appeared on 1 security blocklist and was specifically blocked by PhishDestroy.
At the time of assessment, the domain status was offline, reducing immediate exposure risk. However, historical phishing attribution and multiple security detections indicate that the infrastructure should remain blocked and monitored for reactivation or migration to related assets. Organizations should review historical access logs for connections to the domain, investigate potential credential exposure, and maintain preventive controls against similar phishing infrastructure. Residual risk remains elevated due to prior malicious use and documented security detections.
Процесс реагирования на угрозы
Статус в публичных блок-листах
Технологии · 2 identified
Cloud platform for frontend deployment, optimized for Next.js.
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Анализ VirusTotal
Архивные доказательства
Доказательства и внешние отчеты
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание