detran-espirito-santo-govbr-ipva[.]vercel[.]app
“Serviços DETRAN-ES Veículos”
detran-espirito-santo-govbr-ipva.vercel.app — 隐形 · 可达. 诈骗类型:Generic Phishing. 证据摘要: VirusTotal 2/91 (ADMINUSLabs, Fortinet); cloaking observed; PhishDestroy score 61/100. 注册商: Vercel.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
PhishDestroy identifies an active generic phishing campaign using the domain detran-espirito-santo-govbr-ipva.vercel.app, which impersonates Brazil’s Departamento Estadual de Trânsito do Espírito Santo (DETRAN-ES) IPVA payment portal. The threat does not employ a known drainer kit but relies on visual spoofing to trick users into submitting sensitive personal and financial information. The domain’s naming convention closely mirrors legitimate government portals, increasing the risk of successful deception among Portuguese-speaking users seeking to pay vehicle taxes. This domain resolves to IP address 216.198.79.195 and was registered through Vercel Inc. As of the latest scan, it shows 0 detections on VirusTotal out of 95 engines, indicating it remains undetected by most antivirus solutions. It utilizes a Google Trust Services SSL certificate, which may lend false legitimacy to users. The domain does not appear on known blocklists at this time, and its creation date is not publicly disclosed due to Vercel's privacy protections. The lack of detection and use of a reputable hosting provider (Vercel) and CA (Google Trust Services) suggests this campaign is actively evolving to evade defenses. This domain is currently active and poses a credible threat to individuals attempting to access DETRAN-ES IPVA services. PhishDestroy has flagged this domain with unique seed e6428b and continues to monitor its infrastructure for changes in hosting or certificate issuance. Users are strongly advised to verify the official DETRAN-ES website (detran.es.gov.br) before entering any personal or payment information. Do not click links in unsolicited emails or SMS messages claiming to be from DETRAN-ES. Block the domain at the network level and report any incidents to relevant cybersecurity authorities. While the immediate risk is classified as under investigation, the absence of detections and legitimate appearance warrant heightened caution and proactive blocking.
网络安全情报
威胁响应 Pipeline
公共封禁名单状态
所用技术 · 3 identified
HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 置信度 100%VirusTotal 分析
网站性能分析
Google PageSpeed Insights — mobile performance audit of detran-espirito-santo-govbr-ipva.vercel.app · checked Apr 27, 2026
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。