watersoftenersandfilters-ggvb[.]pages[.]dev
“Suspected phishing site | Cloudflare”
watersoftenersandfilters-ggvb.pages.dev — Contenuto non disponibile. Simulazione del marchio: Genericcloudflare; Tipo di truffa: Credential Phishing. Riepilogo delle prove: VirusTotal 10/95 (ChainPatrol, alphaMountain.ai, BitDefender, CyRadar, Fortinet); URLScan malicious verdict; PhishDestroy score 80/100. Registrar: Cloudflare.
L’analisi dettagliata di PhishDestroy AI resta in inglese per preservare il rapporto forense originale.
Analysis of the domain watersoftenersandfilters-ggvb.pages.dev shows a recent credential‑phishing infrastructure that was taken offline as of the report date. The domain was registered through Cloudflare on September 19, 2025 and resolves to the Cloudflare‑owned address 172.66.47.147, which is located in the United States under ASN 13335. The TLS certificate presented is issued by Google Trust Services (WE1), and the site enforces HSTS while supporting HTTP/3, confirming that the hosting stack is fully Cloudflare‑managed. A scan on VirusTotal recorded ten detections out of ninety‑five security vendors, and the site is listed on a single public blocklist.
Independent threat‑intel feeds such as PhishDestroy have already blocked the domain, and the page title returned by the server is “Suspected phishing site | Cloudflare”, indicating that the site now serves Cloudflare’s default block page with an HTTP 403 status. Gridinsoft’s trust score of zero further reinforces the malicious classification. The available intelligence confirms a credential‑phishing motive but does not reveal the specific brand or login portal being impersonated, nor does it provide a snapshot of the malicious page content. Consequently, the exact phishing vector and any associated payload remain uncertain.
Defenders should continue to deny any network traffic to the domain and its IP address, add the host to local and perimeter blocklists, and monitor for any re‑registration or reuse of the same sub‑domain pattern. Because the infrastructure is hosted on Cloudflare, threat‑hunters should also watch for other domains that share the same nameserver pair (ines.ns.cloudflare.com, jonah.ns.cloudflare.com) or that resolve to the same IP range, as they may indicate a broader campaign. Ongoing collection of URL‑level indicators and any future content captures will be necessary to refine detection rules and to assess whether the phishing operation is part of a larger threat actor’s toolkit.
Pipeline di risposta alle minacce
Stato della lista di blocco pubblica
Informazioni forensi
Tecnologie · 3 identified
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Analisi di VirusTotal
Prove archiviate
Analisi delle prestazioni del sito
Google PageSpeed Insights — mobile performance audit of watersoftenersandfilters-ggvb.pages.dev · checked Apr 11, 2026
Dati e relazioni esterne
Questo sito ti ha influenzato in qualche modo?
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.
Verifica qualsiasi dominio
Analisi delle minacce utilizzando blocklist archiviate, WHOIS, DNS e prove di scansione pubblica
Scansiona oraSegnala un tentativo di phishing
Segnala i domini sospetti al nostro database delle minacce — proteggi la comunità
SegnalaFeed in tempo reale sulle minacce
Segnalazioni recenti di phishing e modifiche osservate della disponibilità
MonitoraRimani informato, rimani al sicuro
Controlla le minacce in tempo reale oppure contesta questa segnalazione se ritieni che si tratti di un falso positivo