folks-finance-dashboard[.]vercel[.]app
“Folks Finance Dashboard”
folks-finance-dashboard.vercel.app — Прикритий · доступний. Тип шахрайства: Generic Phishing. Зведення доказів: VirusTotal 12/91 (ChainPatrol, alphaMountain.ai, BitDefender, CyRadar, ESET); Google Safe Browsing flagged; cloaking observed; PhishDestroy score 100/100. Реєстратор: Vercel.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
This domain, folks-finance-dashboard.vercel.app, is actively flagged as a high-risk phishing site targeting users of Folks Finance, as indicated by its page title and Google Safe Browsing's social engineering classification. Infrastructure analysis reveals it is hosted on Vercel Inc.'s platform, resolving to IP 216.198.79.3 under AS16509 (Amazon.com, Inc.) in the US. The domain was registered on December 13, 2025, and remains operational with an HTTP 200 status, suggesting it is actively serving content. SSL certification is provided by Google Trust Services (WR1), and technologies detected include Node.js, React, Next.js, and Webpack, consistent with modern web applications but not inherently malicious.
Defenders should note that the domain appears on at least one security blocklist (PhishDestroy) and has a Gridinsoft trust score of 0/100, indicating no credibility. While 11 of 95 security vendors on VirusTotal flag this domain, the absence of additional context (e.g., specific payloads, redirect chains, or kit fingerprints) limits deeper classification. The combination of Vercel hosting, a recent registration date, and social engineering flags aligns with common phishing infrastructure patterns. No concrete evidence links this domain to a known phishing kit or campaign beyond the Folks Finance branding implied by the page title.
Recommended actions include blocking the domain at the DNS or proxy level, monitoring for related subdomains or IPs under the same ASN, and reviewing logs for connections from internal networks. If Folks Finance is a known service within your organization, user education and MFA enforcement are advised to mitigate credential harvesting risks. Further analysis of the site's content (e.g., login forms, API calls) would clarify the exact phishing mechanics, but such investigation should be conducted in a controlled environment to avoid exposure.
Розвіддані з мережевої безпеки
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Технології · 6 identified
JavaScript runtime built on Chrome V8 engine for server-side development.
Cloud platform for frontend deployment, optimized for Next.js.
JavaScript library for building user interfaces with component-based architecture.
React framework for production with hybrid static and server rendering.
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Module bundler for modern JavaScript applications.
Аналіз VirusTotal
Архівні докази
Аналіз продуктивності сайту
Google PageSpeed Insights — mobile performance audit of folks-finance-dashboard.vercel.app · checked Mar 2, 2026
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога