6b6ij-4d0-zyk3b-ps98f-dutz[.]pages[.]dev
“Suspected Malware | Cloudflare”
6b6ij-4d0-zyk3b-ps98f-dutz.pages.dev — Non vérifié. Usurpation de l'identité de la marque : Cloudflare; Type d'arnaque : Impersonation. Résumé des preuves: VirusTotal 13/91 (Criminal IP, alphaMountain.ai, BitDefender, Chong Lua Dao, CyRadar); PhishDestroy score 93/100. Bureau d’enregistrement: Cloudflare Pages.
L’analyse détaillée de PhishDestroy AI reste en anglais afin de préserver le relevé forensique original.
Analysis indicates that the domain 6b6ij-4d0-zyk3b-ps98f-dutz.pages.dev is actively engaged in brand impersonation targeting Cloudflare, as confirmed by multiple threat intelligence sources. The domain is hosted on Cloudflare Pages infrastructure and resolves to the IP address 172.66.44.110, associated with Cloudflare, Inc. in California. The page title, 'Suspected Malware | Cloudflare,' directly references the targeted brand, reinforcing the likelihood of impersonation. At the time of assessment, the domain returns an HTTP 403 status, which may indicate restricted access or defensive measures by the hosting provider. Security vendors have flagged this domain, with 15 of 91 engines on VirusTotal detecting it as malicious. The SSL certificate is issued by Google Trust Services (WE1), a common certificate authority for both legitimate and malicious domains, offering no definitive indication of intent. The domain appears on one security blocklist and is specifically blocked by PhishDestroy, further supporting its classification as a high-risk threat. Infrastructure analysis reveals no evidence of a custom phishing kit or additional artifacts beyond the page title and brand impersonation. The exact content and functionality of the site remain unconfirmed, as the domain has not been fully analyzed for payload delivery or user interaction mechanisms. Defenders are advised to treat this domain as an active phishing threat, block it at the network level, and monitor for related indicators of compromise. Given its association with Cloudflare Pages and the absence of additional infrastructure anomalies, this domain may represent a low-effort impersonation attempt rather than a sophisticated campaign.
Processus de réponse aux menaces Pipeline
Statut de la liste de blocage publique
Informations sur les domaines
Détails techniquesDNS, SAN SSL, horodatages
Analyse VirusTotal
Analyse des performances du site
Google PageSpeed Insights — mobile performance audit of 6b6ij-4d0-zyk3b-ps98f-dutz.pages.dev · checked Jul 19, 2026
Données factuelles et rapports externes
Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif