elmatesito042[.]vercel[.]app
“Encuentroooos, fotooossss”
elmatesito042.vercel.app — Gizlenmiş · ulaşılabilir. Dolandırıcılık türü: Credential Phishing. Kanıt özeti: VirusTotal 17/92 (ADMINUSLabs, alphaMountain.ai, BitDefender, Certego, CyRadar); URLQuery 5 alerts; CF Radar malicious; cloaking observed; PhishDestroy score 100/100. Kayıt kuruluşu: Vercel.
Özgün adli kaydı korumak için aşağıdaki ayrıntılı PhishDestroy AI analizi İngilizce bırakılmıştır.
PhishDestroy identifies elmatesito042.vercel.app as an active crypto credential theft domain posing as a trusted brand to steal cryptocurrency wallet access. This domain is part of a current phishing campaign targeting users through deceptive links shared via social media, messaging platforms, or spoofed emails. Once accessed, the page prompts victims to connect their wallets under false pretenses, such as claiming eligibility for airdrops, rewards, or exclusive content. Upon connection, the fraudulent site executes unauthorized blockchain transactions to drain funds directly from victims' wallets without requiring additional authentication. The domain’s infrastructure is designed to mimic legitimate services, leveraging urgency and social engineering to lower victim vigilance and increase success rates. This domain was flagged by 14 out of 95 VirusTotal security vendors, indicating elevated risk levels and potential malicious intent. Registered through Vercel Inc., a legitimate hosting provider often abused by threat actors for rapid deployment, elmatesito042.vercel.app resolves to IP address 64.29.17.131 and operates under a Google Trust Services SSL certificate, which may appear legitimate but is commonly misused to deceive users about site authenticity. The domain’s relatively recent creation and active status suggest it is part of an ongoing campaign rather than an old, recycled threat. Users should treat this domain as malicious and avoid any interaction, including clicking links or entering credentials. If you have visited elmatesito042.vercel.app, disconnect your cryptocurrency wallet immediately to prevent unauthorized access or fund transfers. Do not approve any pending transactions in your wallet interface, as these may be fraudulent. Revoke any wallet permissions granted to unknown or suspicious domains, and scan your device for malware using reliable security software. Report the domain to your wallet provider and relevant cybersecurity authorities to help mitigate further victimization. Remain cautious of unsolicited links or messages claiming to offer crypto rewards, as these are common tactics used to distribute crypto drainers like this one. Stay informed by monitoring updates from threat intelligence platforms and avoid interacting with unverified domains to protect your digital assets.
Ağ Güvenliği İstihbaratı
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| OpenDNS | elmatesito042.vercel.app |
phishing | Phishing Block |
| CIRA Canadian Shield DNS | elmatesito042.vercel.app |
malicious | Sinkholed |
| DNS4EU | elmatesito042.vercel.app |
malicious | Sinkholed |
| Cloudflare DNS | elmatesito042.vercel.app |
malicious | Sinkholed |
| DNS4EU | waust.at |
malicious | Sinkholed |
Tehdit Müdahale Pipeline
Genel Engelleme Listesi Durumu
Teknolojiler · 11 identified
Bootstrap is a free and open-source CSS framework directed at responsive, mobile-first front-end web development. It contains CSS and JavaScript-based design templates for typography, forms, buttons, navigation, and other interface components.
getbootstrap.com %100 güvenShareThis provides free engagement and growth tools (e.g., share buttons, follow buttons, and reaction buttons) for site owners.
sharethis.com %100 güvenjQuery CDN is a way to include jQuery in your website without actually downloading and keeping it your website's folder.
code.jquery.com %100 güvenjQuery is a JavaScript library which is a free, open-source software designed to simplify HTML DOM tree traversal and manipulation, as well as event handling, CSS animation, and Ajax.
jquery.com %100 güvenHTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org %100 güvenGoogle Analytics is a free web analytics service that tracks and reports website traffic.
google.com %100 güven33Across is a technology company focused on solving the challenge of consumer attention for automated advertising.
www.33across.com %100 güvenVirusTotal Analizi
Site Performans Analizi
Google PageSpeed Insights — mobile performance audit of elmatesito042.vercel.app · checked May 7, 2026
Kanıtlar ve Dış Raporlar
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin