nftlucky-box09[.]vercel[.]app
“Deployment Unavailable”
nftlucky-box09.vercel.app — 内容不可用. 诈骗类型:Nft Scam. 证据摘要: VirusTotal 16/93 (ADMINUSLabs, ChainPatrol, Criminal IP, alphaMountain.ai, ArcSight Threat Intelligence); 3 external blocklist matches (Polkadot, Enkrypt, Codeesura); CF Radar malicious; PhishDestroy score 100/100. 注册商: Tucows.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
This domain, nftlucky-box09.vercel.app, operates as a crypto drainer designed to siphon cryptocurrency assets from connected digital wallets. Analysis indicates the site employs deceptive smart contract interactions or malicious transaction prompts to trick users into authorizing unauthorized fund transfers, a tactic increasingly observed in targeted attacks against decentralized finance (DeFi) participants. The domain mimics legitimate NFT or token distribution platforms, leveraging urgency-driven messaging (e.g., "limited-time offers") to exploit victims before they detect the fraudulent activity. Once permissions are granted, the drainer executes automated scripts to empty wallet balances without further user consent, often targeting multiple blockchain networks simultaneously to maximize impact. Infrastructure analysis reveals multiple high-confidence indicators of compromise. The domain resolves to IP address 216.198.79.67, hosted on Amazon Web Services (AS16509), and presents a "Deployment Unavailable" page title, likely a placeholder or fallback state for the malicious payload. It is flagged by 16 out of 95 security vendors on VirusTotal, with additional listings on five specialized blocklists, including those maintained by blockchain security providers. The domain was registered on February 21, 2026, through Tucows Domains Inc., and uses an SSL certificate issued by Google Trust Services (WR1), a common tactic to appear legitimate. The unique seed identifier 8b8ef4 further distinguishes this campaign from other active threats, suggesting coordinated deployment across multiple domains. Users who have interacted with nftlucky-box09.vercel.app should immediately revoke all active smart contract approvals associated with the wallet used on the site. This can be done via blockchain explorers or dedicated revocation tools, ensuring no residual permissions remain. Next, transfer remaining assets to a new, secure wallet address not previously exposed to the domain. Monitor transaction histories for unauthorized activity and report the incident to relevant blockchain security teams or community alert platforms. If private keys or seed phrases were entered, consider the wallet compromised and avoid reusing it. Organizations should update internal blocklists to include this domain and its associated IP, while users should verify all future NFT or token claims through official project channels only.
网络安全情报
威胁响应 Pipeline
公共封禁名单状态
所用技术 · 2 identified
Cloud platform for frontend deployment, optimized for Next.js.
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
VirusTotal 分析
网站性能分析
Google PageSpeed Insights — mobile performance audit of nftlucky-box09.vercel.app · checked Mar 2, 2026
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。