espaminoles452543[.]vercel[.]app
“Encuentroooss D1screetooss”
espaminoles452543.vercel.app — 隐形 · 可达. 证据摘要: VirusTotal 14/94 (ADMINUSLabs, alphaMountain.ai, BitDefender, CyRadar, Ermes); CF Radar malicious; cloaking observed; PhishDestroy score 97/100. 注册商: Vercel.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
PhishDestroy identifies espaminoles452543.vercel.app as an active credential-harvesting domain with elevated risk. This site masquerades as a confidential meeting portal titled “Encuentroooss D1screetooss” to trick users into submitting login credentials. The domain is registered via Vercel Inc. and resolves to IP 64.29.17.195. It holds a Google Trust Services SSL certificate, yet security vendors are highly cautious, with 11 out of 95 flagging this domain. No blocklist data was provided, but the low trust score and high VT detection ratio strongly correlate with malicious intent. The presence of a valid SSL certificate suggests an attempt to appear legitimate, a common tactic in modern phishing campaigns. This domain is currently active and should be treated with extreme caution. The combination of a deceptive page title, trusted SSL issuer, and high VT detection ratio indicates a sophisticated phishing operation. The use of a Vercel subdomain may be leveraged to bypass traditional domain-based filtering. The IP address 64.29.17.195 is associated with Vercel’s infrastructure, which is often abused by threat actors to host phishing pages due to Vercel’s legitimate reputation. The page title’s misspelling (“Encuentroooss D1screetooss”) is a linguistic cue intended to evade keyword-based detection while maintaining visual similarity to target language phrases. To mitigate risk, users should avoid accessing this domain entirely. Organizations should block espaminoles452543.vercel.app at the network perimeter using DNS filtering or firewall rules referencing the domain and IP 64.29.17.195. If credentials were entered, immediately reset passwords on all related accounts and enable multi-factor authentication. Report this domain to your organization’s threat intelligence team or to platforms like Google Safe Browsing, PhishTank, or your email security provider. Monitor for follow-on spear-phishing attempts targeting users who may have fallen victim. This domain should be considered hostile until independently verified as safe.
网络安全情报
威胁响应 Pipeline
公共封禁名单状态
所用技术 · 7 identified
Popular CSS framework for responsive, mobile-first web development.
Cloud platform for frontend deployment, optimized for Next.js.
Legacy JavaScript library — DOM manipulation and AJAX helpers. Still widely present on older sites.
Fast, small JavaScript library simplifying HTML manipulation, event handling, and Ajax.
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Web analytics service tracking website traffic and user behavior.
marketingplatform.google.comVirusTotal 分析
网站性能分析
Google PageSpeed Insights — mobile performance audit of espaminoles452543.vercel.app · checked Apr 14, 2026
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。