cypto-upholdld[.]pages[.]dev
“Suspected phishing site | Cloudflare”
Osservazione memorizzata
Contrasto dei titoli osservato
Riepilogo delle prove
On 24 July 2026 the domain cypto-upholdld.pages.dev was observed hosting a credential phishing page that returned HTTP 403 and displayed the Cloudflare‑generated title “Suspected phishing site | Cloudflare”. The domain resolves to 172.66.47.140, an address owned by AS13335 Cloudflare, Inc. in the United States. Registration data show the domain was created on 21 February 2026 through Cloudflare, Inc., and the authoritative nameservers are collins.ns.cloudflare.com and carmelo.ns.cloudflare.com. TLS termination is provided by a Google Trust Services certificate (WE1) and the site advertised HSTS and HTTP/3 support, indicating modern web stack usage. Reputation services flag the host as highly suspicious.
Google Safe Browsing categorises it as “social engineering”, and PhishDestroy has actively blocked the domain. VirusTotal recorded 12 detections out of 93 scanned vendors, and the domain appears on at least one public blocklist. Independent trust‑scoring services assign near‑zero scores (Gridinsoft 0/100, Scamadviser 1/100). The site’s current status is offline, suggesting the operator may have withdrawn the infrastructure after detection. Evidence confirms a credential‑phishing campaign, but the specific target brand or service being spoofed cannot be derived from the available artefacts; the page title contains no brand reference and no additional content has been disclosed.
Consequently, attribution of the phishing lure remains unknown. Analysts should continue monitoring the IP address 172.66.47.140 and the associated Cloudflare ASN for any re‑use, and incorporate the domain into internal blocklists. Endpoint protection solutions that reference Google Safe Browsing or VirusTotal verdicts will already flag the host. Defensive teams are advised to enforce network‑level deny rules for the domain and to educate users about unsolicited credential requests, especially those that resolve to Cloudflare‑hosted subdomains with generic phishing titles.
Data Coverage
Informazioni sulla sicurezza di rete
Pipeline di risposta alle minacce
Copertura delle blocklist
10 fonti esterne monitorate · snapshot del 12/08/2026
10 fonti esterne monitorate Nessuna corrispondenza
Cronologia del rilevamento
-
Cloudflare Radar
Scansione Cloudflare Radar archiviata · Apri scansione
-
Stato del dominio
Raggiungibile → Non raggiungibile
Tecnologie
3 tecnologie identificate con alta affidabilità
Analisi di VirusTotal
Analisi delle prestazioni del sito
Google PageSpeed Insights — mobile performance audit of cypto-upholdld.pages.dev · checked Apr 13, 2026
Questo sito ti ha influenzato in qualche modo?
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.
Verifica qualsiasi dominio
Analisi delle minacce utilizzando blocklist archiviate, WHOIS, DNS e prove di scansione pubblica
Scansiona oraSegnala un tentativo di phishing
Segnala i domini sospetti al nostro database delle minacce — proteggi la comunità
SegnalaFeed in tempo reale sulle minacce
Segnalazioni recenti di phishing e modifiche osservate della disponibilità
MonitoraRimani informato, rimani al sicuro
Controlla le minacce in tempo reale oppure contesta questa segnalazione se ritieni che si tratti di un falso positivo