help-upold-en[.]pages[.]dev
“Suspected phishing site | Cloudflare”
Gespeicherte Beobachtung
Beobachteter Titelkontrast
Zusammenfassung der Beweislage
On July 24, 2026 the domain help-upold-en.pages.dev was observed delivering a generic credential‑phishing page that returns HTTP 403 and displays the title “Suspected phishing site | Cloudflare”. The domain was created on 21 February 2026 and is hosted on Cloudflare’s network (ASN 13335) with the IP address 172.66.44.76 located in the United States. DNS resolution uses the Cloudflare authoritative nameservers carlane.ns.cloudflare.com and mitchell.ns.cloudflare.com. The TLS certificate presented is issued by Google Trust Services under the WE1 root, confirming the use of a valid HTTPS endpoint. HSTS and HTTP/3 are enabled, indicating modern protocol support.
Reputation data shows the site is currently blocked by PhishDestroy and appears on a single public blocklist. Google Safe Browsing has flagged the domain for social engineering, and nine of ninety‑three VirusTotal scanners have raised alerts, reinforcing the malicious classification. Gridinsoft assigns a trust score of 0 out of 100, reflecting a highly suspicious reputation. No additional intelligence such as targeted brands, malware kits, or observed payloads is available; the only concrete artifact is the page title and the generic “Credential Phishing” label provided in the source data.
Given the combination of a recent registration, Cloudflare hosting, a valid SSL certificate, and multiple independent detections, the infrastructure should be treated as high‑confidence phishing. Defensive teams are advised to add help‑upold‑en.pages.dev to URL filtering and sink‑hole rules, block outbound connections to 172.66.44.76, and monitor for future sub‑domains under the same Cloudflare account. Continuous re‑scanning is recommended, as the site may reactivate or change content. The evidence base for this assessment includes registration metadata, DNS records, TLS details, HTTP response, blocklist entries, Google Safe Browsing classification, VirusTotal vendor flags, and the Gridinsoft trust score.
Data Coverage
Pipeline zur Reaktion auf Sicherheitsbedrohungen
Blocklistenabdeckung
10 überwachte externe Feeds · gespeicherter Stand 10.08.2026
Erkennungszeitleiste
-
Cloudflare Radar
Cloudflare-Radar-Scan gespeichert · Scan öffnen
-
Domainstatus
Erreichbar → Nicht erreichbar
-
Cloudflare Radar
Cloudflare-Radar-Scan gespeichert · Scan öffnen
Forensische Erkenntnisse
Technologien
3 Technologien mit hoher Konfidenz erkannt
VirusTotal-Analyse
Website-Performanceanalyse
Google PageSpeed Insights — mobile performance audit of help-upold-en.pages.dev · checked Apr 13, 2026
Wurden Sie von dieser Website betroffen?
Wenn Sie Kontoanmeldeinformationen, persönliche oder Zahlungsinformationen eingegeben oder eine Datei von dieser Domain heruntergeladen haben, ergreifen Sie sofort Maßnahmen. Nachfolgend finden Sie Ressourcen, die Ihnen helfen, den Vorfall zu melden und sich zu schützen.
Melden Sie sich bei Ihren örtlichen Behörden
Wählen Sie Ihr Land aus, um Offizielle Kontakte im Bereich Cyberkriminalität oder einen Beschwerdeentwurf erstellen → zu erhalten.
Jede beliebige Domain prüfen
Bedrohungsanalyse anhand gespeicherter Blocklisten, WHOIS, DNS und öffentlicher Scan-Beweise
Jetzt scannenPhishing melden
Melden Sie verdächtige Domains an unsere Bedrohungsdatenbank – schützen Sie die Community
MeldenEchtzeit-Bedrohungsfeed
Aktuelle Phishing-Meldungen und beobachtete Verfügbarkeitsänderungen
ÜberwachenBleiben Sie auf dem Laufenden, bleiben Sie sicher
Beobachten Sie aktuelle Bedrohungen oder legen Sie Widerspruch gegen diesen Eintrag ein, wenn Sie der Meinung sind, dass es sich um einen Fehlalarm handelt