uphold-help-io[.]pages[.]dev
“Suspected phishing site | Cloudflare”
ملاحظة محفوظة
تباين العناوين المرصود
ملخص الأدلة
Analysis indicates that uphold-help-io.pages.dev was provisioned on February 21 2026 and is hosted behind Cloudflare’s edge network (ASN 13335, United States). DNS resolution points to 172.66.44.206 and the authoritative name servers are syeef.ns.cloudflare.com and oaklyn.ns.cloudflare.com, confirming that the domain is fully managed by Cloudflare, Inc. The site presented a HTTP 403 response at the time of observation and employed HSTS and HTTP/3, suggesting modern TLS configuration. The SSL certificate is issued by Google Trust Services under the WE1 profile, a common certificate for Cloudflare‑protected sites.
Threat intelligence flags the domain as a credential phishing campaign. VirusTotal recorded 12 detections out of 93 scanners, and the site is listed on a single external blocklist and has been blocked by PhishDestroy. Gridinsoft assigned a trust score of 0 / 100, reinforcing the malicious assessment. The page title returned by the server is “Suspected phishing site | Cloudflare”, which is a generic placeholder rather than a brand‑specific landing page.
Given the limited public artifacts, the exact target brand or login portal being spoofed cannot be confirmed. The evidence points to a fast‑flux‑style deployment using Cloudflare’s CDN to mask the origin and to leverage reputable TLS certificates, a tactic frequently observed in credential‑stealing operations. Defenders should continue to block the domain at network perimeter, update URL filtering lists with the known IP and host, and monitor for any future re‑registration or similar sub‑domains that resolve to the same Cloudflare edge IP range. Additional analysis of the content served when the site is re‑enabled would be required to identify the specific credential collection vectors.
Data Coverage
استخبارات أمن الشبكات
مسار الاستجابة للتهديدات Pipeline
تغطية قوائم الحظر
١٠ مصادر خارجية مراقبة · لقطة محفوظة 10/08/2026
المخطط الزمني للاكتشاف
التقنيات
حُدّدت ٣ تقنيات عالية الثقة
تحليل VirusTotal
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب