pl5iqnogtq[.]pages[.]dev
“Gratulacje”
pl5iqnogtq.pages.dev — Contenu indisponible. Type d'arnaque : Credential Phishing. Résumé des preuves: VirusTotal 0/94; PhishDestroy score 25/100. Bureau d’enregistrement: Cloudflare.
L’analyse détaillée de PhishDestroy AI reste en anglais afin de préserver le relevé forensique original.
This domain is flagged as an elevated-risk phishing site specializing in Polish-language prize scams, as indicated by the page title 'Gratulacje' (Congratulations). The infrastructure is designed to deceive users into believing they have won a prize, a common social engineering tactic targeting Polish-speaking victims. Analysis indicates the domain was operational for a short period before being taken offline, suggesting a disposable phishing campaign. Infrastructure analysis reveals the domain was registered on January 25, 2025, through Cloudflare, Inc., and resolves to the IP address 172.66.44.100. Detection metrics show minimal coverage, with only 1 out of 95 security vendors flagging the domain on VirusTotal. The domain appears on a single security blocklist and has a Gridinsoft trust score of 0/100. Technologies detected include HSTS, Cloudflare CDN, and HTTP/3, while the SSL certificate is issued by Google Trust Services. The use of Cloudflare infrastructure and modern protocols may have been intended to evade detection and lend credibility to the scam. Mitigation for this threat involves blocking the domain and its resolving IP (172.66.44.100) at the network perimeter. Organizations should implement DNS filtering to prevent access to newly registered domains (NRDs) with low reputation scores, particularly those using Cloudflare or similar CDN services. End-user education should emphasize skepticism toward unsolicited prize notifications, especially those delivered via unfamiliar domains. Security teams are advised to monitor for additional domains registered under the same infrastructure or using identical page titles, as threat actors frequently reuse templates across campaigns.
Processus de réponse aux menaces Pipeline
Statut de la liste de blocage publique
Technologies · 3 identified
HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org Confiance à 100 %Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com Confiance à 100 %HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org Confiance à 100 %Analyse VirusTotal
Analyse des performances du site
Google PageSpeed Insights — mobile performance audit of pl5iqnogtq.pages.dev · checked Jun 26, 2026
Données factuelles et rapports externes
Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif