ccehsa-m188[.]pages[.]dev
“MDG188 - Link Alternatif Resmi Menempuh Slot Online Terlisensi Dan Terpopuler No #1”
Zusammenfassung der Beweislage
The domain ccehsa-m188.pages.dev is currently active and flagged as a credential theft operation targeting users of online slot gaming platforms. Analysis indicates this is not a generic phishing attempt but a specialized campaign designed to harvest login credentials, payment details, and personal information from individuals seeking alternative access to licensed gambling sites. The page title, "MDG188 - Link Alternatif Resmi Menempuh Slot Online Terlisensi Dan Terpopuler No #1," explicitly references MDG188, a known online slot brand, suggesting direct impersonation to lend credibility to the fraudulent site. Infrastructure analysis reveals the domain was registered through Cloudflare, Inc. on March 02, 2026, and resolves to the IP address 172.66.46.230, hosted under AS13335 (Cloudflare, Inc.) in the United States. Security vendor detection is notable, with 6 of 95 VirusTotal engines flagging the domain as malicious. The domain appears on one security blocklist and is actively blocked by PhishDestroy. The SSL certificate is issued by Let's Encrypt (serial number E7), a common choice for both legitimate and malicious sites due to its free and automated issuance process. The use of Cloudflare's infrastructure further complicates attribution, as it masks the true origin of the hosting server. Current monitoring confirms the domain remains active and operational. Organizations and individuals are advised to block access to 172.66.46.230 and ccehsa-m188.pages.dev at the network perimeter. Endpoint protection should be updated to include this domain in deny lists, and users should be educated to recognize the specific page title and branding (MDG188) as indicators of fraud. Given the high-risk nature of credential theft, affected users should immediately reset passwords and monitor financial accounts for unauthorized activity. Security teams are encouraged to review logs for connections to the IP or domain to identify potential compromises.
Data Coverage
Erkenntnisse zur Netzwerksicherheit
Pipeline zur Reaktion auf Sicherheitsbedrohungen
Blocklistenabdeckung
10 überwachte externe Feeds · gespeicherter Stand 11.08.2026
Erkennungszeitleiste
-
Cloudflare Radar
Cloudflare-Radar-Scan gespeichert · Scan öffnen
-
Cloudflare Radar
Cloudflare-Radar-Scan gespeichert · Scan öffnen
-
VirusTotal
0 → 6
Forensische Erkenntnisse
VirusTotal-Analyse
Website-Performanceanalyse
Google PageSpeed Insights — mobile performance audit of ccehsa-m188.pages.dev · checked Mar 3, 2026
Wurden Sie von dieser Website betroffen?
Wenn Sie Kontoanmeldeinformationen, persönliche oder Zahlungsinformationen eingegeben oder eine Datei von dieser Domain heruntergeladen haben, ergreifen Sie sofort Maßnahmen. Nachfolgend finden Sie Ressourcen, die Ihnen helfen, den Vorfall zu melden und sich zu schützen.
Melden Sie sich bei Ihren örtlichen Behörden
Wählen Sie Ihr Land aus, um Offizielle Kontakte im Bereich Cyberkriminalität oder einen Beschwerdeentwurf erstellen → zu erhalten.
Jede beliebige Domain prüfen
Bedrohungsanalyse anhand gespeicherter Blocklisten, WHOIS, DNS und öffentlicher Scan-Beweise
Jetzt scannenPhishing melden
Melden Sie verdächtige Domains an unsere Bedrohungsdatenbank – schützen Sie die Community
MeldenEchtzeit-Bedrohungsfeed
Aktuelle Phishing-Meldungen und beobachtete Verfügbarkeitsänderungen
ÜberwachenBleiben Sie auf dem Laufenden, bleiben Sie sicher
Beobachten Sie aktuelle Bedrohungen oder legen Sie Widerspruch gegen diesen Eintrag ein, wenn Sie der Meinung sind, dass es sich um einen Fehlalarm handelt