sync-store-ur85[.]p-lboid22u[.]workers[.]dev
ملخص الأدلة
Sync‑store‑ur85.p‑lboid22u.workers.dev is currently active and serves a page whose title returns “Loading…”. The domain was registered on April 15 2026 through Cloudflare, Inc., and resolves to the Cloudflare‑owned address 172.67.144.175, which is announced by AS13335 in the United States. TLS termination is provided by a Let’s Encrypt certificate (YE2) and the site enforces HSTS while supporting HTTP/3.
Network analysis shows the host is protected by Cloudflare’s edge services, and the domain’s DNS records are not publicly disclosed (nameservers reported as NS_NOT_FOUND). The site returns HTTP 200 on every request, confirming the presence of a functional web server. The page title “Loading…” is a common indicator of a placeholder page used in credential‑harvesting campaigns.
Reputation services assign a zero‑score on the Gridinsoft trust metric (0/100) and the domain appears on a single external blocklist. VirusTotal scans have flagged the domain by 13 of 95 security vendors, and the phishing‑specific blocklist PhishDestroy has already listed it. These signals, combined with the high‑risk classification, point to a credible generic phishing operation targeting users who may be lured by a seemingly innocuous loading screen.
Defenders should block the domain at network perimeter and ensure any browser or email gateway that resolves to 172.67.144.175 is prevented from loading content. Continuous monitoring of Cloudflare‑hosted IP ranges for similar patterns is advised, and incident response teams should treat any credential submissions to this site as compromised. Further forensic investigation of traffic logs may reveal additional infrastructure components that support the campaign.
Data Coverage
مسار الاستجابة للتهديدات Pipeline
تغطية قوائم الحظر
١٠ مصادر خارجية مراقبة · لقطة محفوظة 11/08/2026
التقنيات
حُدّدت ٣ تقنيات عالية الثقة
تحليل VirusTotal
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب