cypto-upholdld[.]pages[.]dev
“Suspected phishing site | Cloudflare”
Gespeicherte Beobachtung
Beobachteter Titelkontrast
Zusammenfassung der Beweislage
On 24 July 2026 the domain cypto-upholdld.pages.dev was observed hosting a credential phishing page that returned HTTP 403 and displayed the Cloudflare‑generated title “Suspected phishing site | Cloudflare”. The domain resolves to 172.66.47.140, an address owned by AS13335 Cloudflare, Inc. in the United States. Registration data show the domain was created on 21 February 2026 through Cloudflare, Inc., and the authoritative nameservers are collins.ns.cloudflare.com and carmelo.ns.cloudflare.com. TLS termination is provided by a Google Trust Services certificate (WE1) and the site advertised HSTS and HTTP/3 support, indicating modern web stack usage. Reputation services flag the host as highly suspicious.
Google Safe Browsing categorises it as “social engineering”, and PhishDestroy has actively blocked the domain. VirusTotal recorded 12 detections out of 93 scanned vendors, and the domain appears on at least one public blocklist. Independent trust‑scoring services assign near‑zero scores (Gridinsoft 0/100, Scamadviser 1/100). The site’s current status is offline, suggesting the operator may have withdrawn the infrastructure after detection. Evidence confirms a credential‑phishing campaign, but the specific target brand or service being spoofed cannot be derived from the available artefacts; the page title contains no brand reference and no additional content has been disclosed.
Consequently, attribution of the phishing lure remains unknown. Analysts should continue monitoring the IP address 172.66.47.140 and the associated Cloudflare ASN for any re‑use, and incorporate the domain into internal blocklists. Endpoint protection solutions that reference Google Safe Browsing or VirusTotal verdicts will already flag the host. Defensive teams are advised to enforce network‑level deny rules for the domain and to educate users about unsolicited credential requests, especially those that resolve to Cloudflare‑hosted subdomains with generic phishing titles.
Data Coverage
Erkenntnisse zur Netzwerksicherheit
Pipeline zur Reaktion auf Sicherheitsbedrohungen
Blocklistenabdeckung
10 überwachte externe Feeds · gespeicherter Stand 12.08.2026
Erkennungszeitleiste
-
Cloudflare Radar
Cloudflare-Radar-Scan gespeichert · Scan öffnen
-
Domainstatus
Erreichbar → Nicht erreichbar
Technologien
3 Technologien mit hoher Konfidenz erkannt
VirusTotal-Analyse
Website-Performanceanalyse
Google PageSpeed Insights — mobile performance audit of cypto-upholdld.pages.dev · checked Apr 13, 2026
Wurden Sie von dieser Website betroffen?
Wenn Sie Kontoanmeldeinformationen, persönliche oder Zahlungsinformationen eingegeben oder eine Datei von dieser Domain heruntergeladen haben, ergreifen Sie sofort Maßnahmen. Nachfolgend finden Sie Ressourcen, die Ihnen helfen, den Vorfall zu melden und sich zu schützen.
Melden Sie sich bei Ihren örtlichen Behörden
Wählen Sie Ihr Land aus, um Offizielle Kontakte im Bereich Cyberkriminalität oder einen Beschwerdeentwurf erstellen → zu erhalten.
Jede beliebige Domain prüfen
Bedrohungsanalyse anhand gespeicherter Blocklisten, WHOIS, DNS und öffentlicher Scan-Beweise
Jetzt scannenPhishing melden
Melden Sie verdächtige Domains an unsere Bedrohungsdatenbank – schützen Sie die Community
MeldenEchtzeit-Bedrohungsfeed
Aktuelle Phishing-Meldungen und beobachtete Verfügbarkeitsänderungen
ÜberwachenBleiben Sie auf dem Laufenden, bleiben Sie sicher
Beobachten Sie aktuelle Bedrohungen oder legen Sie Widerspruch gegen diesen Eintrag ein, wenn Sie der Meinung sind, dass es sich um einen Fehlalarm handelt