me1q1a1e[.]vercel[.]app
“美治科技 | 一站式智能客服解决方案_在线客服系统_客服机器人_工单系统_呼叫中心”
me1q1a1e.vercel.app — 内容不可用. 证据摘要: VirusTotal 0/93; PhishDestroy score 25/100. 注册商: Tucows.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
The domain me1q1a1e.vercel.app was registered on February 21 2026 through Tucows Domains Inc. and is hosted on Amazon’s AS16509 network, resolving to IP address 76.76.21.93 located in the United States. The site served a page titled "美治科技 | 一站式智能客服解决方案_在线客服系统_客服机器人_工单系统_呼叫中心", indicating a purported Chinese‑language customer‑service solution. Infrastructure analysis shows the site was deployed on Vercel and enforces HTTP Strict Transport Security, while its TLS certificate was issued by Google Trust Services under the WR1 certificate profile.
HTTP responses returned status code 451, and the domain has been taken offline at the time of this assessment. Threat intelligence indicates the domain is listed on a single security blocklist and has been blocked by PhishDestroy, suggesting it was identified as part of a phishing campaign targeting users seeking online customer support. VirusTotal scanned the URL with 93 antivirus and URL‑reputation engines, none of which raised a detection; however, the absence of a detection does not constitute verification of safety.
The limited evidence base leaves several uncertainties: the exact phishing payload, any credential‑harvesting forms, and whether additional malicious infrastructure is associated with the same IP range remain unconfirmed. Defenders should continue to monitor the IP address 76.76.21.93 for any resurgence of malicious activity, enforce outbound traffic controls to block connections to this domain and related Vercel endpoints, and incorporate the domain into internal blocklists. Further investigation using web‑content capture, sandbox execution, and network traffic analysis is recommended should the domain become active again, to determine the full scope of the phishing kit and potential data exfiltration vectors.
威胁响应 Pipeline
公共封禁名单状态
所用技术 · 2 identified
Cloud platform for frontend deployment, optimized for Next.js.
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
VirusTotal 分析
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。