sddftyrdyfwaru[.]vercel[.]app
“Facebook”
sddftyrdyfwaru.vercel.app — 隐形 · 可达. 品牌冒充:Facebook; 诈骗类型:Brand Impersonation. 证据摘要: VirusTotal 22/91 (ADMINUSLabs, Criminal IP, alphaMountain.ai, BitDefender, Chong Lua Dao); URLQuery 10 det.; URLScan malicious verdict; CF Radar malicious; cloaking observed; PhishDestroy score 100/100. 注册商: Vercel.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
This domain, sddftyrdyfwaru.vercel.app, is flagged for high-risk brand impersonation targeting Facebook. Analysis of the page title confirms the fraudulent activity, with the domain explicitly mimicking Facebook's login interface to deceive users into entering credentials. No direct evidence of a crypto drainer or malware payload was observed, but the domain aligns with credential harvesting tactics commonly deployed in phishing campaigns. Infrastructure analysis reveals the domain resolves to the IP address 216.198.79.131, hosted by Vercel, Inc. in the United States. The SSL certificate is issued by Google Trust Services (WR1), a common but not inherently malicious provider. VirusTotal detection metrics show 14 out of 95 security vendors flagging the domain as malicious. The domain appears on one security blocklist and is registered through Vercel Inc., with no historical registration data publicly available. Google Safe Browsing status was not explicitly provided, but the presence on a blocklist and VirusTotal detections confirm its malicious classification. As of the latest assessment, sddftyrdyfwaru.vercel.app remains active, posing an ongoing threat to users. Response actions should include immediate blacklisting of the domain and IP across security controls, alongside monitoring for related subdomains or newly registered lookalike domains. Organizations are advised to block access to this domain at the network level and alert users to the risk of credential theft. Given the domain's persistence, continued vigilance is required, particularly for Facebook users or those accessing social media platforms via unsecured networks.
网络安全情报
威胁响应 Pipeline
公共封禁名单状态
所用技术 · 2 identified
HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 置信度 100%VirusTotal 分析
网站性能分析
Google PageSpeed Insights — mobile performance audit of sddftyrdyfwaru.vercel.app · checked May 23, 2026
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。