heliusrpcfixai[.]pages[.]dev
“Suspected Phishing | Cloudflare”
ملخص الأدلة
Analysis indicates that heliusrpcfixai.pages.dev was registered on October 15, 2025 through the Cloudflare Pages service. The domain resolves to the IPv4 address 172.66.46.214, which is owned by Cloudflare's edge network and is commonly used for hosting short‑lived malicious pages. The site is currently listed as active and classified as a generic phishing threat with an elevated risk rating. Defensive feeds have recorded a single blocklist entry, and the domain is explicitly blocked by the PhishDestroy service.
VirusTotal scans show that 2 of 91 security vendors have raised detections for the domain, confirming that at least a minority of scanners recognize malicious behavior. The limited number of detections suggests that the campaign may be recent or intentionally low‑profile, but the presence of any detections together with the blocklist entry provides sufficient operational evidence of abuse. The available intelligence does not include details such as SSL certificate characteristics, HTTP response codes, page title, or additional threat‑intel identifiers, leaving the full scope of the phishing payload unknown. Consequently, defenders cannot assess which credentials or services may be targeted beyond the generic phishing classification.
Nonetheless, the combination of a recent creation date, Cloudflare Pages hosting, active blocklist status, and multiple vendor detections warrants proactive mitigation. Organizations should add heliusrpcfixai.pages.dev to DNS and URL filtering policies, monitor network logs for connections to 172.66.46.214, and consider sharing the indicator with upstream threat‑intel feeds. Continuous re‑evaluation is recommended as additional analysis, such as payload inspection or sandbox execution, becomes available.
Data Coverage
مسار الاستجابة للتهديدات Pipeline
تغطية قوائم الحظر
١٠ مصادر خارجية مراقبة · لقطة محفوظة 13/08/2026
المخطط الزمني للاكتشاف
-
حالة النطاق
يمكن الوصول إليه ← يتعذر الوصول إليه
معلومات النطاق
التفاصيل التقنيةDNS وأسماء TLS والطوابع الزمنية
التقنيات
حُدّدت ٣ تقنيات عالية الثقة
تحليل VirusTotal
تحليل أداء الموقع
Google PageSpeed Insights — mobile performance audit of heliusrpcfixai.pages.dev · checked Jul 29, 2026
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب