fb-login3shrii[.]vercel[.]app
“Facebook”
fb-login3shrii.vercel.app — 未验证. 品牌冒充:Facebook; 诈骗类型:Credential Phishing. 证据摘要: VirusTotal 21/91 (ADMINUSLabs, Criminal IP, alphaMountain.ai, BitDefender, CyRadar); URLQuery 3 alerts; Google Safe Browsing flagged; PhishDestroy score 100/100. 注册商: Vercel.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
This domain, fb-login3shrii.vercel.app, is flagged as a high-risk brand impersonation threat specifically targeting Facebook users. Analysis indicates the site mimics legitimate Facebook login pages, aiming to harvest user credentials through deceptive authentication interfaces. The threat type is classified as credential theft via brand impersonation, a common vector for account compromise and subsequent unauthorized access to personal data or financial information. Infrastructure analysis reveals the domain resolves to the IP address 64.29.17.3, associated with Vercel, Inc. in the United States. The domain was registered through Vercel, with an anomalous creation date of May 19, 2026, suggesting potential timestamp manipulation or misconfiguration. Detection metrics show 19 out of 95 security vendors on VirusTotal have flagged this domain as malicious. It appears on one security blocklist, specifically PhishDestroy, and is actively marked as phishing by Google Safe Browsing. The SSL certificate is issued by Google Trust Services (WR1), which, while legitimate, does not mitigate the inherent risk posed by the domain's fraudulent intent. Mitigation against this threat requires immediate action from both end-users and network administrators. Users should avoid interacting with fb-login3shrii.vercel.app and any similar domains, particularly those mimicking Facebook’s branding. Network-level protections should include blocking the domain and its resolving IP (64.29.17.3) at firewalls or DNS filtering systems. Organizations are advised to monitor for credential reuse attempts, as harvested credentials may be exploited across multiple platforms. Additionally, security teams should investigate logs for connections to the domain or IP to identify potentially compromised accounts. User education on recognizing brand impersonation tactics, such as scrutinizing URLs and verifying SSL certificate details, remains critical in preventing credential theft.
网络安全情报
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Cloudflare DNS | fb-login3shrii.vercel.app |
malicious | Sinkholed |
| OpenDNS | fb-login3shrii.vercel.app |
phishing | Phishing Block |
| DNS4EU | fb-login3shrii.vercel.app |
malicious | Sinkholed |
威胁响应 Pipeline
公共封禁名单状态
已保存的截图
域名情报
技术细节DNS、SSL SAN、时间戳
VirusTotal 分析
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。