ke-mehserle-eider[.]pages[.]dev
“Suspected phishing site | Cloudflare”
保存済み観測
観測されたタイトルの差異
証拠の概要
PhishDestroy identifies ke-mehserle-eider.pages.dev as an active generic phishing domain leveraging a Cloudflare Pages deployment to impersonate a legitimate service. The threat type is credential harvesting under the generic_phishing classification, with no direct association to a specific brand or drainer kit identified in current intelligence. The domain's structure suggests opportunistic mimicry of trustworthy domains to deceive users into entering sensitive information, likely targeting login credentials or financial data through a spoofed authentication interface. Analysis of the technical infrastructure reveals a reliance on Cloudflare's Pages service, which provides an immediate veneer of legitimacy while obscuring the true origin of the threat. This approach exploits the widespread trust in Cloudflare's infrastructure to bypass initial scrutiny by both users and automated detection systems.
Technical indicators for this domain confirm its elevated risk profile. The domain resolves to IP address 172.66.44.146 and is registered through Cloudflare, Inc., which complicates traditional takedown or blocking efforts due to Cloudflare's role as both registrar and hosting provider. The SSL certificate is issued by Google Trust Services, further enhancing the domain's appearance of legitimacy. VirusTotal analysis shows 16 out of 95 security vendors flagging this domain, indicating partial but not universal detection across industry tools. Additionally, the domain appears on 2 known security blocklists, including OpenPhish and PhishingDB, underscoring its malicious classification. These blocklists serve as critical early warning systems for organizations and individual users, but the domain's continued availability suggests ongoing evasion tactics or delays in coordinated response efforts.
The current status of ke-mehserle-eider.pages.dev remains active as of the latest assessment, with no evidence of takedown or remediation. Response actions have included blocking by OpenPhish and PhishingDB, as well as partial detection by 16% of VirusTotal engines, but these measures have not resulted in the domain's removal from the active threat landscape. The remaining risk is elevated due to the domain's persistent accessibility, reliance on trusted infrastructure, and the potential for further iterations or similar domains to emerge. Users are strongly advised to avoid interacting with this domain entirely and report it to relevant authorities or security platforms if encountered. Organizations should incorporate this domain into their threat intelligence feeds and firewall rules to prevent accidental exposure. Proactive monitoring of similar domains leveraging Cloudflare Pages or other trusted services is recommended to mitigate future risks associated with this attack vector.
Data Coverage
ネットワークセキュリティインテリジェンス
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | ke-mehserle-eider.pages.dev |
malicious | Sinkholed |
| Cloudflare DNS | ke-mehserle-eider.pages.dev |
malicious | Sinkholed |
| Quad9 DNS | ke-mehserle-eider.pages.dev |
malicious | Sinkholed |
脅威対応 Pipeline
ブロックリストの確認範囲
監視対象の外部情報源 10 件 · 保存スナップショット 2026年8月12日
使用技術
高確信度で特定された技術:3 件
VirusTotalによる分析
サイトパフォーマンス分析
Google PageSpeed Insights — mobile performance audit of ke-mehserle-eider.pages.dev · checked May 11, 2026
このサイトによって何か影響を受けましたか?
アカウント資格情報、個人情報、支払い情報を入力した場合、またはこのドメインからファイルをダウンロードした場合は、すぐに対処してください。インシデントを報告し、自分自身を守るのに役立つリソースを以下に示します。
お住まいの地域の当局へ報告してください
サイバー犯罪の公式連絡先 または 苦情草稿を作成する → を取得するには、国を選択してください。
任意のドメインを確認する
保存されたブロックリスト、WHOIS、DNS、および公開スキャン証拠を使用した脅威分析
今すぐスキャンフィッシングを報告する
不審なドメインを当社の脅威データベースに報告してください — コミュニティを守りましょう
レポートリアルタイム脅威情報フィード
最近のフィッシングレポートと観察された可用性の変化
監視最新情報を入手し、安全を確保しましょう
リアルタイムの脅威を監視するか、誤検知だと思われる場合はこのリストに異議を申し立ててください