espaminoles452543[.]vercel[.]app
“Encuentroooss D1screetooss”
espaminoles452543.vercel.app — Прикритий · доступний. Зведення доказів: VirusTotal 14/94 (ADMINUSLabs, alphaMountain.ai, BitDefender, CyRadar, Ermes); CF Radar malicious; cloaking observed; PhishDestroy score 97/100. Реєстратор: Vercel.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
PhishDestroy identifies espaminoles452543.vercel.app as an active credential-harvesting domain with elevated risk. This site masquerades as a confidential meeting portal titled “Encuentroooss D1screetooss” to trick users into submitting login credentials. The domain is registered via Vercel Inc. and resolves to IP 64.29.17.195. It holds a Google Trust Services SSL certificate, yet security vendors are highly cautious, with 11 out of 95 flagging this domain. No blocklist data was provided, but the low trust score and high VT detection ratio strongly correlate with malicious intent. The presence of a valid SSL certificate suggests an attempt to appear legitimate, a common tactic in modern phishing campaigns. This domain is currently active and should be treated with extreme caution. The combination of a deceptive page title, trusted SSL issuer, and high VT detection ratio indicates a sophisticated phishing operation. The use of a Vercel subdomain may be leveraged to bypass traditional domain-based filtering. The IP address 64.29.17.195 is associated with Vercel’s infrastructure, which is often abused by threat actors to host phishing pages due to Vercel’s legitimate reputation. The page title’s misspelling (“Encuentroooss D1screetooss”) is a linguistic cue intended to evade keyword-based detection while maintaining visual similarity to target language phrases. To mitigate risk, users should avoid accessing this domain entirely. Organizations should block espaminoles452543.vercel.app at the network perimeter using DNS filtering or firewall rules referencing the domain and IP 64.29.17.195. If credentials were entered, immediately reset passwords on all related accounts and enable multi-factor authentication. Report this domain to your organization’s threat intelligence team or to platforms like Google Safe Browsing, PhishTank, or your email security provider. Monitor for follow-on spear-phishing attempts targeting users who may have fallen victim. This domain should be considered hostile until independently verified as safe.
Розвіддані з мережевої безпеки
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Технології · 7 identified
Popular CSS framework for responsive, mobile-first web development.
Cloud platform for frontend deployment, optimized for Next.js.
Legacy JavaScript library — DOM manipulation and AJAX helpers. Still widely present on older sites.
Fast, small JavaScript library simplifying HTML manipulation, event handling, and Ajax.
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Web analytics service tracking website traffic and user behavior.
marketingplatform.google.comАналіз VirusTotal
Аналіз продуктивності сайту
Google PageSpeed Insights — mobile performance audit of espaminoles452543.vercel.app · checked Apr 14, 2026
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога