cratdappclaim[.]vercel[.]app
“CratD2C”
cratdappclaim.vercel.app — Контент недоступний. Тип шахрайства: Crypto Scam. Зведення доказів: VirusTotal 1/95 (Trustwave); 3 external blocklist matches (Polkadot, Enkrypt, Codeesura); PhishDestroy score 74/100. Реєстратор: Tucows.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
The domain cratdappclaim.vercel.app was registered on February 21, 2026 through Tucows Domains Inc. and is hosted on the Vercel platform, as indicated by the detected Vercel technology fingerprint and the presence of HTTP Strict Transport Security (HSTS). The site presented an HTTP 451 response and the page title “CratD2C” before being taken offline. The TLS certificate was issued by Google Trust Services under the WR1 profile, confirming a valid HTTPS endpoint at the time of capture. Network resolution points to the IPv4 address 64.29.17.131, which belongs to Amazon.com, Inc. (AS16509) and resolves to a location in the United States. VirusTotal recorded a single positive detection out of 95 scanning engines, and the domain appears on four independent security blocklists, including PhishDestroy, Polkadot, Enkrypt, and Codeesura.
The combined evidence aligns with the classification of a crypto‑drainer scam, a subset of crypto‑related fraud that typically attempts to exfiltrate digital assets from unsuspecting victims. No additional artifacts such as login forms, redirects, or payloads have been observed because the site is currently offline. Consequently, the precise mechanisms used to lure victims or to interact with cryptocurrency wallets remain unknown. Likewise, the presence of any malicious scripts or third‑party services could not be verified.
Defenders should continue to block the domain at network perimeter and DNS layers, monitor for any resurgence of the same IP address or Vercel sub‑domain patterns, and add the associated IP to internal deny lists. Given the legitimate‑looking SSL certificate, reliance on certificate validation alone is insufficient; threat‑intel feeds that incorporate the observed blocklist entries and the VirusTotal detection should be consulted for early warning. Analysts should also watch for newly registered Vercel‑hosted domains that reuse the “CratD” naming convention, as they may represent follow‑on infrastructure.
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Технології · 2 identified
Cloud platform for frontend deployment, optimized for Next.js.
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Аналіз VirusTotal
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога