online-usbank-secure[.]vercel[.]app
“404: NOT_FOUND”
online-usbank-secure.vercel.app — Doğrulanmamış. Dolandırıcılık türü: Banking Phishing. Kanıt özeti: VirusTotal 18/93 (ADMINUSLabs, Criminal IP, alphaMountain.ai, BitDefender, CRDF); CF Radar malicious; PhishDestroy score 95/100. Kayıt kuruluşu: Tucows.
Özgün adli kaydı korumak için aşağıdaki ayrıntılı PhishDestroy AI analizi İngilizce bırakılmıştır.
This domain, online-usbank-secure.vercel.app, was identified as a credential theft operation targeting customers of a major U.S. financial institution. The site was designed to mimic legitimate online banking portals, tricking visitors into entering sensitive login credentials, account numbers, or multifactor authentication codes. Such stolen information is typically used for unauthorized account access, fraudulent transactions, or sold on underground forums. The threat extends beyond immediate financial loss, as compromised credentials may enable further identity theft or targeted follow-up attacks. Analysis indicates the domain was registered on February 21, 2026, through Tucows Domains Inc., an unusual creation date suggesting potential domain spoofing or backdating. At the time of detection, the site resolved to IP address 64.29.17.67, hosted within Amazon.com, Inc.'s AS16509 network in the United States. Security vendor assessments on VirusTotal revealed 18 out of 95 engines flagged the domain as malicious, with one confirmed blocklist entry from PhishDestroy. The SSL certificate, issued by Google Trust Services (WR1), provided a false sense of security while failing to prevent detection by automated security systems. Individuals who visited online-usbank-secure.vercel.app should assume their credentials may have been compromised. Immediate action is required: reset passwords for the affected financial account and any other services where the same credentials were reused. Enable multifactor authentication if not already active, using app-based or hardware tokens rather than SMS. Monitor account statements for unauthorized transactions and report suspicious activity to the financial institution. If personal or financial data was entered, consider placing a fraud alert or credit freeze with major credit bureaus to prevent new account openings. Network administrators should block the domain and associated IP (64.29.17.67) at perimeter defenses to prevent further exposure.
Ağ Güvenliği İstihbaratı
Tehdit Müdahale Pipeline
Genel Engelleme Listesi Durumu
Teknolojiler · 2 identified
Cloud platform for frontend deployment, optimized for Next.js.
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
VirusTotal Analizi
Kanıtlar ve Dış Raporlar
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin