io-phmt-walet[.]pages[.]dev
“Suspected phishing site | Cloudflare”
ملاحظة محفوظة
تباين العناوين المرصود
ملخص الأدلة
The domain io-phmt-walet.pages.dev was observed hosting a credential phishing page that Cloudflare itself flagged with the title “Suspected phishing site | Cloudflare”. The site was created on 21 February 2026 and was immediately served behind Cloudflare’s network (ASN 13335, United States). DNS resolution points to 172.66.47.161, which is owned by Cloudflare, Inc., and the authoritative nameservers are dara.ns.cloudflare.com and gerardo.ns.cloudflare.com. The SSL certificate presented is issued by Google Trust Services under the WE1 identifier, indicating a valid TLS chain but offering no assurance about the content behind the certificate. Google Safe Browsing classified the URL as social engineering, and the domain appears on a single security blocklist, where it was also blocked by the PhishDestroy service.
VirusTotal analysis recorded 12 of 93 scanning engines flagging the domain, reinforcing the malicious assessment. Additional telemetry shows a Gridinsoft trust score of 0 out of 100, and the HTTP response returned a 403 status code before the site was taken offline. Detected technologies include HTTP/3, HSTS, and Cloudflare’s edge protection. The evidence collectively points to a high‑risk credential‑phishing infrastructure that leveraged Cloudflare’s free hosting to obscure its origin.
Because the site is currently offline, immediate exploitation risk is reduced, but the domain may be re‑activated or cloned for future campaigns. Defenders should ensure that any outbound traffic to the IP address 172.66.47.161 is monitored and blocked where appropriate, add the domain to internal blocklists, and correlate logs for attempts to contact the nameservers or resolve the domain. Continuous monitoring of Cloudflare‑hosted subdomains for similar patterns is recommended, as the attacker can rapidly generate new pages under the same parent domain.
Data Coverage
مسار الاستجابة للتهديدات Pipeline
تغطية قوائم الحظر
١٠ مصادر خارجية مراقبة · لقطة محفوظة 11/08/2026
المخطط الزمني للاكتشاف
الاستخبارات الجنائية الرقمية
تحليل VirusTotal
تحليل أداء الموقع
Google PageSpeed Insights — mobile performance audit of io-phmt-walet.pages.dev · checked Apr 21, 2026
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب