186tyesy[.]vercel[.]app
“Poczta - Najlepsza Poczta, największe załączniki - WP”
Збережене виявлення
Виявлено маскування
- Тип маскування
content_split- Оцінка маскування
- 1/6
Зведення доказів
This domain, 186tyesy.vercel.app, is currently engaged in a high-risk phishing campaign impersonating the WP webmail service, specifically targeting Polish-speaking users. Analysis indicates the threat type as brand impersonation phishing, designed to harvest login credentials by mimicking the legitimate WP Poczta interface. The page title, "Poczta - Najlepsza Poczta, największe załączniki - WP," directly replicates the branding of the authentic WP webmail portal, increasing the likelihood of successful deception. As of the latest verification, the domain remains active and operational, posing an ongoing risk to unsuspecting users. Infrastructure analysis reveals the domain is registered through Vercel Inc., a platform commonly exploited for rapid deployment of phishing pages due to its ease of use and free hosting capabilities. The domain resolves to the IP address 216.198.79.195, which has been flagged by 13 of 95 security vendors on VirusTotal for malicious activity. No additional historical registration data or creation date is publicly available, limiting temporal attribution. However, the detection ratio of 13/95 indicates moderate to high confidence in malicious classification among security vendors. The absence of widespread blocklisting suggests the campaign may still be in an early or targeted phase, evading broader detection mechanisms. Current assessment confirms the domain remains active and continues to host the fraudulent WP-themed phishing page. Organizations and end-users are advised to implement immediate mitigations, including blocking the domain and IP at network perimeters, deploying endpoint protection rules to detect and prevent access, and conducting user awareness training to recognize brand impersonation tactics. Given the high-risk nature of credential theft, affected users should be instructed to reset passwords for any accounts accessed via the fraudulent portal. Continuous monitoring of related infrastructure is recommended, as threat actors frequently rotate domains and IPs to sustain campaign effectiveness.
Data Coverage
Процес реагування на загрози Pipeline
Перевірка за блок-листами
10 зовнішніх джерел під наглядом · знімок від 13.08.2026
Аналіз VirusTotal
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога