sf-redi[.]vercel[.]app
“Redirecting...”
sf-redi.vercel.app — 内容不可用. 证据摘要: VirusTotal 0/93; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 66/100. 注册商: Tucows.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
Analysis of sf-redi.vercel.app indicates that the domain was registered through Tucows Domains Inc on 21 February 2026. The DNS configuration uses Vercel‑provided nameservers (ns1‑ns4.vercel‑dns‑3.com) and the site is hosted on Amazon’s AS16509 network, resolving to the IPv4 address 64.29.17.131 located in the United States. A Google Trust Services certificate (WR1) is present, and HTTP requests return a 404 status with the page title “Redirecting…”, suggesting that the content is either removed or deliberately hidden.
The domain has been scanned by VirusTotal, where 93 antivirus engines have examined the site, yet no current detections are reported; this absence of flags does not constitute a safety guarantee. Independent blocklist monitoring shows inclusion on three security blocklists, specifically PhishDestroy, MetaMask, and SEAL, confirming that external threat‑intelligence feeds consider the domain malicious. The presence of Vercel technology and HSTS indicates a modern web stack, but does not mitigate the observed risk.
Because the site is currently offline, immediate content analysis is limited, and the exact phishing vector or target brand remains unknown. Defenders should continue to block traffic to the IP address 64.29.17.131 and the domain itself at DNS and proxy layers, update intrusion‑prevention signatures to include the observed nameserver pattern and certificate issuer, and monitor for any re‑activation or redirection to new endpoints. Additional investigation may focus on correlating the certificate serial number with other reported malicious domains, and reviewing any historical request logs that could reveal victim interaction before the takedown.
威胁响应 Pipeline
公共封禁名单状态
所用技术 · 2 identified
Cloud platform for frontend deployment, optimized for Next.js.
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
VirusTotal 分析
存档证据
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。