crackaf-bubbles-frontend[.]vercel[.]app
“Exchange | PancakeSwap - ...”
crackaf-bubbles-frontend.vercel.app — 未验证. 品牌冒充:PancakeSwap; 诈骗类型:Crypto Scam. 证据摘要: VirusTotal 19/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, Cluster25, CyRadar); URLQuery 100 det.; URLScan malicious verdict; CF Radar malicious; PhishDestroy score 100/100. 注册商: Tucows.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
This domain, crackaf-bubbles-frontend.vercel.app, is actively engaged in brand impersonation, specifically targeting PancakeSwap, a decentralized exchange platform. Analysis confirms its current status as active, with no indications of takedown or mitigation as of the latest intelligence. The domain mimics the legitimate PancakeSwap interface, as evidenced by the page title 'Exchange | PancakeSwap - ...', aiming to deceive users into disclosing sensitive credentials or interacting with malicious contracts. Infrastructure analysis reveals the domain is flagged by 16 of 95 security vendors on VirusTotal, indicating a consensus among detection engines regarding its malicious nature. The domain was registered through Tucows Domains Inc. on February 21, 2026, an anomalous creation date suggesting potential typosquatting or preemptive registration for malicious use. It resolves to the IP address 64.29.17.131 and is associated with an SSL certificate issued by Google Trust Services (WR1). The domain appears on 2 security blocklists, further corroborating its high-risk classification. Notably, the use of Vercel's hosting infrastructure may provide the threat actor with agility in deploying and rotating malicious content. Current status remains active, posing an ongoing risk to users who may inadvertently interact with the domain. Organizations and individuals are advised to block the domain and its associated IP address (64.29.17.131) at the network perimeter. End-users should be alerted to verify domain authenticity before engaging with decentralized finance platforms, particularly those resembling PancakeSwap. Security teams are recommended to monitor for related indicators of compromise, including the SSL certificate thumbprint and any subdomains or redirects associated with this infrastructure. Proactive hunting for similar impersonation domains using the seed '7d1d2e' may uncover additional threats in this campaign.
安全信号
网络安全情报
威胁响应 Pipeline
公共封禁名单状态
所用技术 · 4 identified
Cloud platform for frontend deployment, optimized for Next.js.
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Tag management system for deploying marketing and analytics tags.
tagmanager.google.comWeb analytics service tracking website traffic and user behavior.
marketingplatform.google.comVirusTotal 分析
存档证据
网站性能分析
Google PageSpeed Insights — mobile performance audit of crackaf-bubbles-frontend.vercel.app · checked Mar 1, 2026
网站配置分析
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。