bep20-usdt-one[.]vercel[.]app
“Transfer Trust Wallet”
bep20-usdt-one.vercel.app — 隐形 · 可达. 品牌冒充:Trust Wallet; 诈骗类型:Brand Impersonation. 证据摘要: VirusTotal 6/91 (alphaMountain.ai, Emsisoft, Fortinet, Gridinsoft, Netcraft); URLQuery 1 alert; 1 external blocklist match (ScamSniffer); cloaking observed; PhishDestroy score 91/100. 注册商: Vercel.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
This domain is flagged as a high-risk crypto drainer specializing in brand impersonation targeting Trust Wallet users. Analysis indicates the site employs deceptive transfer prompts to initiate unauthorized cryptocurrency transactions, specifically mimicking Trust Wallet's interface to harvest wallet credentials and drain funds from connected accounts. Infrastructure analysis reveals the domain bep20-usdt-one.vercel.app was registered on April 28, 2026, through Vercel Inc. and currently resolves to IP address 64.29.17.131, located in the United States under Vercel's hosting infrastructure. The domain appears on two security blocklists, including PhishDestroy and ScamSniffer, and is flagged by 1 out of 95 security vendors on VirusTotal. The SSL certificate is issued by Google Trust Services (WR1), which while legitimate, does not mitigate the malicious intent of the domain. The page title 'Transfer Trust Wallet' directly aligns with the observed attack pattern of simulating wallet transfer processes to deceive victims. Mitigation requires immediate action from both users and security teams. Users should avoid interacting with this domain, particularly when prompted to connect wallets or input recovery phrases. Security teams are advised to block the domain and its resolving IP (64.29.17.131) at the network level, update endpoint protection rules to detect and prevent access, and monitor for related infrastructure (e.g., Vercel-hosted subdomains with similar naming patterns). Wallet providers should issue alerts to users about this specific impersonation campaign, emphasizing that legitimate wallet transfers never require entering recovery phrases or private keys on external sites. Additionally, monitoring for newly registered Vercel domains with cryptocurrency-related keywords may help preempt similar threats.
网络安全情报
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| YARAhub by abuse.ch | bep20-usdt-one.vercel.app/main.js |
malware | Detects file containing Telegram Bot API |
威胁响应 Pipeline
公共封禁名单状态
所用技术 · 3 identified
JSDelivr is a free public CDN for open-source projects. It can serve web files directly from the npm registry and GitHub repositories without any configuration.
www.jsdelivr.com 置信度 100%HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 置信度 100%VirusTotal 分析
网站性能分析
Google PageSpeed Insights — mobile performance audit of bep20-usdt-one.vercel.app · checked Apr 28, 2026
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。