pub-11e6504d5d9a40ff97bcd3d5ee476ec8[.]r2[.]dev
“Not Found”
pub-11e6504d5d9a40ff97bcd3d5ee476ec8.r2.dev — सामग्री अनुपलब्ध. ब्रांड प्रतिरूपण: Genericemail; घोटाले का प्रकार: Generic Phishing. साक्ष्य सारांश: VirusTotal 17/94 (ADMINUSLabs, Criminal IP, alphaMountain.ai, BitDefender, Chong Lua Dao); URLQuery 4 alerts; URLScan malicious verdict; CF Radar malicious; PhishDestroy score 95/100. रजिस्ट्रार: Cloudflare R2.
मूल फॉरेंसिक रिकॉर्ड सुरक्षित रखने के लिए नीचे का विस्तृत PhishDestroy AI विश्लेषण अंग्रेज़ी में रखा गया है।
PhishDestroy identifies pub-11e6504d5d9a40ff97bcd3d5ee476ec8.r2.dev as an active crypto drainer phishing domain posing extreme risk to cryptocurrency users. This domain employs sophisticated social engineering tactics to trick victims into connecting cryptocurrency wallets and initiating unauthorized transfers. The infrastructure is designed to drain digital assets within minutes of wallet connection, making it particularly dangerous for DeFi users and NFT collectors. Security researchers classify this as a high-risk threat due to its high conversion rate and ability to bypass traditional security measures. This domain was flagged by 17 out of 95 VirusTotal security vendors, placing it in the top 1% of malicious domains. The domain resolves to IP address 104.18.54.45, which is associated with Cloudflare's R2 storage service. The SSL certificate was issued by Let's Encrypt, indicating the threat actors are using valid encryption to appear legitimate. This domain appears on three major blocklists including OpenPhish, PhishingArmy, and OISD, confirming its malicious status. The domain uses Cloudflare's infrastructure to evade detection and maintain availability, while the r2.dev subdomain indicates it's hosted on Cloudflare R2 storage, a legitimate service being abused for malicious purposes. To mitigate this crypto drainer threat, immediately block the domain pub-11e6504d5d9a40ff97bcd3d5ee476ec8.r2.dev at your network perimeter using DNS filtering or firewall rules. Cryptocurrency users should verify all wallet connection requests through out-of-band communication channels and never approve transactions from unknown sources. Implement wallet connection monitoring tools that alert users to suspicious contract interactions. Organizations should update their threat intelligence feeds with this IOC and consider deploying browser isolation technologies for cryptocurrency-related activities. The combination of valid SSL certificates and major cloud hosting services makes this threat particularly challenging to detect, requiring layered security approaches that combine network-level blocking with user education and advanced endpoint protection.
नेटवर्क सुरक्षा इंटेलिजेंस
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Cloudflare DNS | pub-11e6504d5d9a40ff97bcd3d5ee476ec8.r2.dev |
malicious | Sinkholed |
| OpenDNS | pub-11e6504d5d9a40ff97bcd3d5ee476ec8.r2.dev |
phishing | Phishing Block |
| DNS4EU | pub-11e6504d5d9a40ff97bcd3d5ee476ec8.r2.dev |
malicious | Sinkholed |
| Quad9 DNS | pub-11e6504d5d9a40ff97bcd3d5ee476ec8.r2.dev |
malicious | Sinkholed |
धमकी प्रतिक्रिया पाइपलाइन
सार्वजनिक ब्लॉकलिस्ट स्थिति
तकनीकें · 2 identified
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comवायरसटोटल विश्लेषण
साइट प्रदर्शन विश्लेषण
Google PageSpeed Insights — mobile performance audit of pub-11e6504d5d9a40ff97bcd3d5ee476ec8.r2.dev · checked Mar 29, 2026
साक्ष्य और बाहरी रिपोर्टें
क्या आप इस साइट से प्रभावित हुए?
यदि आपने खाता क्रेडेंशियल, व्यक्तिगत या भुगतान जानकारी दर्ज की है, या इस डोमेन से कोई फ़ाइल डाउनलोड की है, तो तुरंत कार्रवाई करें। घटना की रिपोर्ट करने और अपनी सुरक्षा करने में आपकी सहायता के लिए नीचे संसाधन दिए गए हैं।
अपने स्थानीय अधिकारियों को रिपोर्ट करें
आधिकारिक साइबर अपराध संपर्क, या एक शिकायत ड्राफ्ट बनाएं → प्राप्त करने के लिए अपना देश चुनें।
किसी भी डोमेन की जाँच करें
संग्रहीत ब्लॉकलिस्ट, WHOIS, DNS और सार्वजनिक स्कैन साक्ष्य का उपयोग करके खतरे का विश्लेषण
अभी स्कैन करेंफ़िशिंग की रिपोर्ट करें
संदिग्ध डोमेन हमारे थ्रेट डेटाबेस में जमा करें — समुदाय की सुरक्षा करें
रिपोर्ट करेंसीधा खतरा फीड
हाल की फ़िशिंग रिपोर्टें और उपलब्धता में परिवर्तन देखे गए
निगरानी करेंजानकारी में रहें, सुरक्षित रहें
लाइव खतरों की निगरानी करें या यदि आपको लगता है कि यह एक गलत सकारात्मक है तो इस लिस्टिंग को चुनौती दें।