186tyesy[.]vercel[.]app
“Poczta - Najlepsza Poczta, największe załączniki - WP”
186tyesy.vercel.app — 隐形 · 可达 (HTTP 404). 诈骗类型:Brand Impersonation. 证据摘要: VirusTotal 14/91 (BitDefender, CyRadar, ESET, Emsisoft, Fortinet); cloaking observed; PhishDestroy score 92/100. 注册商: Vercel.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
This domain, 186tyesy.vercel.app, is currently engaged in a high-risk phishing campaign impersonating the WP webmail service, specifically targeting Polish-speaking users. Analysis indicates the threat type as brand impersonation phishing, designed to harvest login credentials by mimicking the legitimate WP Poczta interface. The page title, "Poczta - Najlepsza Poczta, największe załączniki - WP," directly replicates the branding of the authentic WP webmail portal, increasing the likelihood of successful deception. As of the latest verification, the domain remains active and operational, posing an ongoing risk to unsuspecting users. Infrastructure analysis reveals the domain is registered through Vercel Inc., a platform commonly exploited for rapid deployment of phishing pages due to its ease of use and free hosting capabilities. The domain resolves to the IP address 216.198.79.195, which has been flagged by 13 of 95 security vendors on VirusTotal for malicious activity. No additional historical registration data or creation date is publicly available, limiting temporal attribution. However, the detection ratio of 13/95 indicates moderate to high confidence in malicious classification among security vendors. The absence of widespread blocklisting suggests the campaign may still be in an early or targeted phase, evading broader detection mechanisms. Current assessment confirms the domain remains active and continues to host the fraudulent WP-themed phishing page. Organizations and end-users are advised to implement immediate mitigations, including blocking the domain and IP at network perimeters, deploying endpoint protection rules to detect and prevent access, and conducting user awareness training to recognize brand impersonation tactics. Given the high-risk nature of credential theft, affected users should be instructed to reset passwords for any accounts accessed via the fraudulent portal. Continuous monitoring of related infrastructure is recommended, as threat actors frequently rotate domains and IPs to sustain campaign effectiveness.
威胁响应 Pipeline
公共封禁名单状态
VirusTotal 分析
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。