domain Scam
Crypto Investment Landing Page Scam
High-pressure funnels promise impossible APYs and embed unlicensed wallets or merchant IDs. WebVetted dissects the hosting stack, wallet destinations, and previously linked rug pulls before you fund them.
- Guaranteed returns or referral multipliers with no risk disclosures.
- Wallet address rotates through text fields rather than a trusted checkout.
- Testimonials use AI headshots or link to unrelated LinkedIn profiles.
- Use the Website Safety Checker to capture infrastructure details and hosting history.
- Lookup every wallet or merchant ID mentioned and compare to previous WebVetted casework.
- Escalate to your exchange or bank with the preserved evidence before disputing transfers.
📌 Case study
One landing page claimed to be Binance-backed yet resolved to a pocket hosting account in Lagos. Another reused footage from a Canadian hedge fund promo while pushing deposits to a Tron wallet recycled across seven scams.
domain Scam
Fake App Store Clone Download Page
Fraudsters build fake App Store or Play Store mirrors that deliver sideloaded malware or solicit payments. WebVetted reviews certificate data, bundle IDs, and download links to expose fakes.
- Page demands direct APK downloads instead of linking to official stores.
- Developer contact info lists generic Gmail addresses or WhatsApp numbers.
- Version history and review counts remain static for months.
- Use the Website Safety Checker to document where the download actually originates.
- Cross-check the bundle ID and developer name within the real App Store or Google Play.
- If installed, remove the rogue app and reset any credentials shared during setup.
📌 Case study
A banking trojan crew pushed a “Play Store” page that sideloaded an SMS grabber signed by a random shell company. Another clone used the Apple brand but rerouted buyers to a Shopify checkout for “activation keys.”
domain Scam
Fake Charity Donation Page
Scammers mirror relief charities after every disaster, leaning on emotional photos and cloned press releases. WebVetted looks at EIN data, processing partners, and DNS age to separate real aid groups from cash-grabs.
- Donation form routes payments to personal PayPal or crypto wallets.
- No mention of the organization’s registration number or board of directors.
- Press badges or testimonials cite outlets that never ran the claimed story.
- Scan the URL with the Website Safety Checker and download the dossier.
- Cross-check the charity name against government registries before donating.
- Forward findings to the legitimate nonprofit so they can warn donors and pursue takedowns.
📌 Case study
Analysts flagged a “wildfire fund” that reused UNICEF photos while money flowed to a private Cash App. Another case copied Doctors Without Borders copy but hosted the form on a throwaway Wix domain registered hours earlier.
domain Scam
Fake SaaS Login Page
Phishing crews spin up carbon-copy login portals for CRM and finance tools, siphoning credentials before users realize the domain is off. WebVetted inspects SSL metadata, script destinations, and prior abuse reports to prove the clone is rogue.
- URL tacks the brand name onto an unrelated TLD or adds filler terms like secure-login.
- Form posts to an IP or script path that never appears on the legitimate vendor site.
- Fonts, CDN files, or account recovery widgets that normally load from first-party domains are missing or broken.
- Run the URL through the Website Safety Checker to capture hosting, WHOIS, and malware context.
- Compare SSL certificates and script inventories against the legitimate SaaS domain before logging in.
- Reset passwords and revoke sessions for any teammate who interacted with the clone.
📌 Case study
We recently dismantled a batch of Monday.com clones that forwarded passwords to a Telegram bot. Another incident involved Salesforce-lookalike pages that proxied MFA codes through a compromised WordPress plugin.
domain Scam
Instant Loan Approval Bait
Instant approval funnels promise same-day cash once you upload sensitive IDs, then resell the data or charge bogus fees. WebVetted benchmarks SSL age, ownership, and payment endpoints to prove the funnel is just harvesting identities.
- Requests full SSN, bank logins, or paycheck stubs before any disclosures.
- Claims to approve everyone regardless of credit or employment documentation.
- Application steps hosted on mixed domains with no privacy policy.
- Put the domain into the Website Safety Checker to collect the legal entities operating it.
- Compare privacy terms and lender names against state licensing databases.
- If information was submitted, freeze credit and file an FTC identity theft report with your evidence bundle.
📌 Case study
We investigated a “90-second payday” site where the form fed directly into a lead broker tied to ransomware crews. Another lure demanded a processing fee via gift card, then ghosted applicants once codes were sent.