nomi-swap[.]pages[.]dev
“Suspected phishing site | Cloudflare”
ملاحظة محفوظة
تباين العناوين المرصود
ملخص الأدلة
The domain nomi-swap.pages.dev was observed as a crypto‑focused phishing site and is currently taken offline. Infrastructure analysis shows the domain resolves to IP address 104.21.96.1, which belongs to AS13335 Cloudflare, Inc. and is geolocated in the United States. The authoritative nameservers are blair.ns.cloudflare.com and finley.ns.cloudflare.com, both operated by Cloudflare. The site presented a TLS certificate issued by Google Trust Services / WE1, indicating a valid HTTPS endpoint, and the HTTP response returned a 403 status code, consistent with Cloudflare’s generic phishing block page titled “Suspected phishing site | Cloudflare.” Registration data reveals the domain was created on February 21, 2026 through Cloudflare, Inc. The technology stack includes HSTS, Cloudflare services, and HTTP/3 support.
Reputation signals are uniformly negative: Gridinsoft assigns a trust score of 0/100, Scamadviser rates the domain at 11/100, and the site appears on two independent blocklists—PhishDestroy and ScamSniffer—both of which have flagged it as malicious. VirusTotal analysis shows that one of ninety‑three scanning engines identified the domain as suspicious. The risk level is elevated, reflecting the combination of a recent creation date, low trust scores, and active blocklist listings. Defenders should immediately add nomi-swap.pages.dev and its resolved IP 104.21.96.1 to deny lists across web proxies, DNS filtering solutions, and endpoint firewalls.
Continuous monitoring of the domain’s registration and DNS records is advised to detect any re‑registration attempts. Given the Cloudflare front‑end, threat actors may shift to alternative subdomains; security teams should consider broader pattern matching on the “pages.dev” suffix and the observed nameserver pair. Incident response teams should treat any alerts related to this domain as high priority, isolate affected user sessions, and verify that no credential or cryptocurrency wallet data were exfiltrated.
Data Coverage
مسار الاستجابة للتهديدات Pipeline
تغطية قوائم الحظر
١٠ مصادر خارجية مراقبة · لقطة محفوظة 12/08/2026
المخطط الزمني للاكتشاف
-
حالة النطاق
يمكن الوصول إليه ← يتعذر الوصول إليه
-
Cloudflare Radar
تم حفظ فحص Cloudflare Radar · فتح الفحص
معلومات المجتمع
بلاغ مجتمعي واحد
الفئةPHISHING
@hitterace Telegram
الاستخبارات الجنائية الرقمية
تحليل VirusTotal
تحليل أداء الموقع
Google PageSpeed Insights — mobile performance audit of nomi-swap.pages.dev · checked Apr 12, 2026
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب