tta-cms-web[.]pages[.]dev
“Aanmelden bij uw account”
साक्ष्य सारांश
The domain tta-cms-web.pages.dev has been observed delivering a Microsoft‑brand impersonation campaign. The site presents a login page titled “Aanmelden bij uw account”, which mimics the language of Microsoft account authentication. The campaign is currently listed as active and its risk level is under investigation. The infrastructure is already flagged by the PhishDestroy blocklist and appears on one additional security blocklist. Technical analysis shows the domain resolves to the IP address 40.126.32.74, which belongs to the Cloudflare network (AS13335) and is geolocated in the United States. The domain is hosted behind Cloudflare’s edge service, using the nameservers sreeni.ns.cloudflare.com and yevgen.ns.cloudflare.com. TLS termination is provided by Google Trust Services under the WE1 certificate, and HTTP Strict Transport Security (HSTS) is enforced. The web server returns an HTTP 302 redirect, likely steering victims to a secondary payload host. The page’s visual design aligns with a cryptocurrency‑themed scam, as indicated by the “cryptocurrency” classification in the intelligence feed. The site carries a Gridinsoft trust score of 0 out of 100, reflecting a high confidence of malicious intent. Despite the lack of detections on VirusTotal (0/95), the low trust score and active blocklist entries suggest the domain is being used for credential harvesting. Defenders should add 40.126.32.74 and the full domain to network deny lists, monitor DNS queries for the associated Cloudflare nameservers, and enforce email filtering rules that detect the Dutch‑language login phrase “Aanmelden bij uw account”. Continuous threat‑intelligence feeds should be consulted for any new indicators, and any compromised credentials should be forced to reset. Given the active status, organizations should treat this infrastructure as a high‑priority indicator of compromise.
Data Coverage
धमकी प्रतिक्रिया पाइपलाइन
ब्लॉकलिस्ट कवरेज
10 निगरानी वाले बाहरी स्रोत · संग्रहीत स्नैपशॉट 11/08/2026
तकनीकें
1 उच्च-विश्वसनीयता वाली तकनीक पहचानी गई
वायरसटोटल विश्लेषण
क्या आप इस साइट से प्रभावित हुए?
यदि आपने खाता क्रेडेंशियल, व्यक्तिगत या भुगतान जानकारी दर्ज की है, या इस डोमेन से कोई फ़ाइल डाउनलोड की है, तो तुरंत कार्रवाई करें। घटना की रिपोर्ट करने और अपनी सुरक्षा करने में आपकी सहायता के लिए नीचे संसाधन दिए गए हैं।
अपने स्थानीय अधिकारियों को रिपोर्ट करें
आधिकारिक साइबर अपराध संपर्क, या एक शिकायत ड्राफ्ट बनाएं → प्राप्त करने के लिए अपना देश चुनें।
किसी भी डोमेन की जाँच करें
संग्रहीत ब्लॉकलिस्ट, WHOIS, DNS और सार्वजनिक स्कैन साक्ष्य का उपयोग करके खतरे का विश्लेषण
अभी स्कैन करेंफ़िशिंग की रिपोर्ट करें
संदिग्ध डोमेन हमारे थ्रेट डेटाबेस में जमा करें — समुदाय की सुरक्षा करें
रिपोर्ट करेंसीधा खतरा फीड
हाल की फ़िशिंग रिपोर्टें और उपलब्धता में परिवर्तन देखे गए
निगरानी करेंजानकारी में रहें, सुरक्षित रहें
लाइव खतरों की निगरानी करें या यदि आपको लगता है कि यह एक गलत सकारात्मक है तो इस लिस्टिंग को चुनौती दें।