Güvenlik raporuna geç
Checked 09.08.2026 Ref 18E93C9A

MALICIOUS — CRITICAL

cross-pay.vercel.app: Confirmed Across Protocol Impersonation

cross-pay[.]vercel[.]app

Analysis of the domain cross-pay.vercel.app indicates confirmed brand impersonation targeting Across Protocol, a known cross-chain bridge service.

92/100 evidence score · Critical
VirusTotal
9/94
Blocklists
2 · MetaMask, SEAL
Kullanılabilirlik
Gizlenmiş · ulaşılabilir · HTTP 200
Report / Add Evidence Appeal this listing
2026-03-24 11:29 UTCGizlenmiş · ulaşılabilir · HTTP 200

Do not enter credentials, seed phrases, payment details, or personal information on this domain.

⚠️
Bu alan adı, zararlı olarak işaretlenmiştir
Güvenlik motorları bir algılama bildiriyor: 9. Bir eşleşme bildiren genel engellenenler listeleri: 2. Çok dikkatli olun — kimlik bilgilerini veya kişisel bilgileri girmeyin.
Jump to section
Rapor özeti

cross-pay.vercel.app — Gizlenmiş · ulaşılabilir (HTTP 200). Marka kimliğine bürünme: Across; Dolandırıcılık türü: Wallet/seed Phishing. Kanıt özeti: VirusTotal 9/94 (ChainPatrol, alphaMountain.ai, BitDefender, CyRadar, ESET); 2 external blocklist matches (MetaMask, SEAL); cloaking observed; PhishDestroy score 92/100. Kayıt kuruluşu: Vercel.

Özgün adli kaydı korumak için aşağıdaki ayrıntılı PhishDestroy AI analizi İngilizce bırakılmıştır.

Evidence Analysis

Ref 18E93C9A

Analysis of the domain cross-pay.vercel.app indicates confirmed brand impersonation targeting Across Protocol, a known cross-chain bridge service. The domain was registered on March 13, 2026, through Vercel Inc. and remains active as of July 12, 2026. Infrastructure analysis reveals it resolves to IP address 64.29.17.131 and is hosted on Vercel's platform, with HSTS enabled. The domain appears on three security blocklists and is explicitly blocked by SEAL, MetaMask, and PhishDestroy, confirming its malicious classification. VirusTotal detection data shows 9 of 95 security vendors flagging the domain as malicious, though this represents a minority of engines and should not be interpreted as definitive proof of compromise. The SSL certificate is issued by Google Trust Services, which does not inherently indicate legitimacy given the prevalence of free, automated certificate issuance. Gridinsoft assigns a trust score of 0/100, further supporting its classification as high-risk. No specific phishing kit or exact page content has been analyzed, so the precise mechanics of the scam remain unconfirmed. However, the combination of brand impersonation, recent registration, and active blocking by multiple security vendors strongly suggests credential harvesting or fraudulent transaction activity. Defenders should treat this domain as malicious and implement blocking measures at the DNS or network level. Given its continued activity, monitoring for related infrastructure (e.g., subdomains, linked IPs) is recommended.

Stored source results

Recorded verdicts and infrastructure observations for this domain.

VirusTotal
VirusTotal
9 det.
URLScan
URLScan
TLS sertifikası
Google Trust Services
Hosting
Vercel
Yaş
5 mo
Gözlemlenen durum
Gizlenmiş · ulaşılabilir 200
PhishDestroy
DestroyList
Listede
Veri kapsamı12 recorded checks
VirusTotal 9 / 94 URLQuery rapor saklandı — ayrıntılı karar bekleniyor PhishStats checked — no match recorded OTX no community references CF Radarı scan completed URLScan capture saklanan rapor URLScan verdict değerlendirme yok DNS engellemeleri 14 kontrol edildi — engelleme yok TLS valid certificate, 75d WHOIS 5 mo old Ekran görüntüsü 2 captures · 2 sources Yönlendirme zinciri araştırılmadı
Ağ Güvenliği İstihbaratı
Free Hosting Detected Vercel
This domain is hosted on Vercel (free hosting platform). Free hosting platforms are commonly used for both legitimate testing/development and malicious purposes. Additional context is needed for a def

Tehdit Müdahale Pipeline

Keşif
Checks
Reports
Kullanılabilirlik
12/14

Genel Engelleme Listesi Durumu

Kaydedilen görüntü

Etki Alanı Analizi

Alan adı
Sunucu / ASN Vercel · AS16509 AMAZON-02 - Amazon.com, Inc., US
IP Context Vercel shared edge origin IP hidden Edge-IP itibarı bu etki alanıyla ilişkilendirilmez.
Platform sağlayıcısı Vercel US(US)
Kötüye kullanım iletişim bilgisiabuse@vercel.com
IP adresi 64.29.17.131 CDN
Coğrafi konumUS Walnut, US
AS16509 · Amazon.com, Inc.
Kaynak IP, bir CDN proxy'sinin arkasına gizlenir. Uç adresine ilişkin Ters IP sonuçları ilgisiz kiracılar içerir; Kaynağı bulmak için pasif DNS veya sertifika şeffaflığı verileri gerekir.
Cloaking Cloaking Detected Content split · score 1/6
alive_content: raw=ok; http=200; via=https_proxy; server=Vercel
server: Vercel
checked 09.08.2026
HTTP Durumu200
Teknik ayrıntılarDNS, SSL SAN’ları, zaman damgaları
İlk Kez Tespit Edildi13.03.2026
DOM Analysisanalyzed 24.03.2026score 15/1002 brand signals
IoC Extractionscanned 29.07.20260 wallet · 0 Telegram IoCs
Submitted URLhttp://cross-pay.vercel.app/
TLS Fingerprint
TLS Observationvalid from 26.02.2026scanned 15.03.2026
TLS SAN Domainsvercel.app
Favicon Hash
Impersonates
Across MetaMask
TLS sertifikası
Valid transport encryption · Düzenleyen Google Trust Services · valid for 75 days
Teknolojiler · 2 identified
Vercel
PaaS CDN

Cloud platform for frontend deployment, optimized for Next.js.

HSTS
Güvenlik

HTTP Strict Transport Security — forces browsers to use HTTPS connections only.

Detected via Cloudflare Radar · Wappalyzer engine
Bu Alan Adını Bildir Kanıt sunun ve başkalarını korumaya yardımcı olun

VirusTotal Analizi

9 / 94 güvenlik sağlayıcıları bu alanı işaretledi
View on VT
Last analyzed Previous stored snapshot: 4 detections
ChainPatrol
alphaMountain.ai
BitDefender
CyRadar
ESET
Forcepoint ThreatSeeker
Fortinet
G-Data
Sophos
Site Performans Analizi

Google PageSpeed Insights — mobile performance audit of cross-pay.vercel.app · checked Jul 13, 2026

96
Good
Performance
FCP
1.05s
First Contentful Paint
LCP
2.7s
Largest Contentful Paint
CLS
0
Cumulative Layout Shift
TBT
0ms
Total Blocking Time
SI
2.68s
Speed Index
Powered by Google PageSpeed Insights · Mobile strategy · Scores: 90-100 Good 50-89 Needs Work 0-49 Poor
Kanıtlar ve Dış RaporlarIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
If credentials were compromised, report immediately. Do not engage with recovery scammers.

Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.

Europol
AB ülkeniz için resmi raporlama kanalını bulun
National police directory
Kurtarma dolandırıcılarına dikkat edin! Suçlular, araştırmacı, avukat veya kurtarma görevlisi gibi davranarak mağdurlarla tekrar iletişime geçebilir. Peşin ücret ödemeyin veya kimlik bilgilerinizi paylaşmayın. Geri ödeme dolandırıcılığı hakkında daha fazla bilgi edinin →

Yerel Yetkililere Bildirin

resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.

97 ülke rehberi
Yapay zeka destekli taslak — olay ayrıntıları yapay zeka sağlayıcısı tarafından işlenir Kendiniz inceleyin ve gönderin
Bu Raporu YerleştirRead-only HTML widget
HTML · IFRAME

Bu Raporu Yerleştir

Bu tehdit bilgisini web sitenizde veya blogunuzda paylaşın

embed.html
<iframe
  src="https://phishdestroy.io/tr/embed/domain/cross-pay.vercel.app"
  title="PhishDestroy threat report for cross-pay.vercel.app"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>