webmail-bell-one[.]vercel[.]app
“Deployment Unavailable”
webmail-bell-one.vercel.app — 内容不可用. 诈骗类型:Credential Phishing. 证据摘要: VirusTotal 15/93 (ADMINUSLabs, Criminal IP, alphaMountain.ai, BitDefender, CyRadar); URLQuery 2 alerts; CF Radar malicious; PhishDestroy score 95/100. 注册商: Tucows.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
Analysis of the domain webmail-bell-one.vercel.app indicates it was actively involved in a credential phishing campaign targeting users of a Canadian telecommunications provider. The domain was registered on February 21, 2026, through Tucows Domains Inc. and hosted on Vercel’s platform, resolving to the IP address 216.198.79.3 within Amazon.com, Inc.’s AS16509 network in the United States. The SSL certificate, issued by Google Trust Services under the WR1 intermediate, remains valid, though this does not mitigate the domain’s malicious intent. As of July 24, 2026, the domain returned an HTTP 451 status code, typically associated with legal restrictions or content unavailability, and displayed a 'Deployment Unavailable' page title. This suggests the phishing infrastructure was either voluntarily taken offline or disrupted by the hosting provider.
Detection engines on VirusTotal flagged the domain as malicious, with 15 of 93 security vendors marking it as a threat. Additionally, the domain appeared on one security blocklist, specifically PhishDestroy. Infrastructure analysis reveals the use of Vercel’s hosting services, a common tactic among threat actors due to the platform’s free tier and ease of deployment. The presence of HTTP Strict Transport Security (HSTS) headers further aligns with phishing campaigns seeking to appear legitimate by enforcing encrypted connections.
While the exact content of the phishing page remains unanalyzed, the domain’s classification as a credential phishing site is supported by its naming convention, which closely resembles a legitimate webmail portal. Defenders should treat this domain as compromised and ensure it is blocked at the network level. Organizations targeted by similar campaigns are advised to monitor for credential theft attempts and educate users on recognizing phishing domains hosted on legitimate cloud platforms.
网络安全情报
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Cloudflare DNS | webmail-bell-one.vercel.app |
malicious | Sinkholed |
| DNS4EU | webmail-bell-one.vercel.app |
malicious | Sinkholed |
威胁响应 Pipeline
公共封禁名单状态
所用技术 · 2 identified
Cloud platform for frontend deployment, optimized for Next.js.
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
VirusTotal 分析
网站性能分析
Google PageSpeed Insights — mobile performance audit of webmail-bell-one.vercel.app · checked Mar 2, 2026
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。