arcium-top-chad-gallary[.]vercel[.]app
“Purple Dream Gallery”
arcium-top-chad-gallary.vercel.app — 隐形 · 可达. 诈骗类型:Credential Phishing. 证据摘要: VirusTotal 4/91 (ChainPatrol, alphaMountain.ai, Forcepoint ThreatSeeker, LevelBlue); cloaking observed; PhishDestroy score 91/100. 注册商: Vercel.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
This domain, arcium-top-chad-gallary.vercel.app, is flagged as an active credential theft phishing site designed to harvest user login credentials. Analysis of the page title, 'Purple Dream Gallery,' suggests an attempt to impersonate a legitimate gallery or digital asset platform, potentially targeting users seeking access to exclusive content or services. The infrastructure lacks overt indicators of a crypto drainer kit but exhibits characteristics consistent with credential harvesting, including form-based data capture mechanisms observed in preliminary sandbox analysis. Technical indicators reveal the domain is hosted on Vercel Inc. infrastructure and resolves to IP address 216.198.79.131, geolocated within the United States under AS16509 (Amazon.com, Inc.). The SSL certificate is issued by Google Trust Services (WR1), a common feature in both legitimate and malicious deployments. Detection metrics show a VirusTotal score of 2/95, indicating limited but present identification by security vendors. The domain appears on one security blocklist and is currently classified as active. No creation date metadata is available through public WHOIS or passive DNS records, limiting temporal attribution. Current status confirms the domain remains operational, with no takedown or sinkholing actions observed as of analysis. The registrar, Vercel Inc., has not issued a public response or suspension notice. Remaining risk is assessed as high due to the domain's active credential harvesting capability, low detection rate, and hosting on a platform frequently exploited for rapid deployment of phishing pages. Users are advised to avoid interaction with the domain, verify URLs through official sources, and employ multi-factor authentication to mitigate credential exposure risks. Network-level blocking of the IP 216.198.79.131 is recommended for enterprise environments.
威胁响应 Pipeline
公共封禁名单状态
取证情报
所用技术 · 4 identified
Cloud platform for frontend deployment, optimized for Next.js.
Free public CDN for open-source projects, serving files from npm and GitHub.
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
VirusTotal 分析
存档证据
网站性能分析
Google PageSpeed Insights — mobile performance audit of arcium-top-chad-gallary.vercel.app · checked Mar 2, 2026
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。