service-cloudflare[.]com
PhishDestroy identifies service-cloudflare.com as an active Cloudflare credential harvesting site posing as the legitimate Cloudflare service. This domain mimics official branding to trick users into entering login credentials or sensitive payment information, with threat actors leveraging Cloudflare’s trusted reputation to bypass security filters. The fraudulent domain was registered through Cloudflare’s own registrar on March 30, 2026, a highly unusual and suspicious practice that raises immediate red flags for domain authenticity. Security intelligence confirms this domain resolves to IP 38.54.108.85, uses a Let’s Encrypt SSL certificate, and has already been blocked by two major phishing blocklists: OpenPhish and PhishingArmy.
VirusTotal analysis reveals that 13 out of 95 security vendors have flagged service-cloudflare.com as malicious, indicating elevated threat potential with confirmed phishing activity targeting Cloudflare users. The domain’s recent creation date—just days ago—combined with its registration through Cloudflare’s own registrar, suggests a coordinated impersonation campaign likely launched to exploit users during a period of low scrutiny. This tactic is consistent with advanced phishing operations that abuse trusted infrastructure to increase credibility and evade detection by automated security systems.
If you visited service-cloudflare.com or entered any credentials, immediately change your Cloudflare account password and enable two-factor authentication. Scan your device for malware using a reputable antivirus tool such as Malwarebytes or Windows Defender. Report the domain to Cloudflare’s abuse team and your IT administrator if on a corporate network. Avoid clicking any links or downloading files from this domain. Monitor financial accounts and enable transaction alerts. For future protection, bookmark the official Cloudflare login page at cloudflare.com/login and verify URLs carefully before entering credentials. Stay vigilant—this domain is actively malicious and should be treated as a confirmed phishing threat.
ネットワークセキュリティインテリジェンス
脅威対応 Pipeline
ブロックリストの確認範囲
10 件の情報源 · 2026年8月10日 に同期
保存済みキャプチャ
ドメイン・インテリジェンス
技術詳細DNS、TLS 名、タイムスタンプ
ICANN OVERSIGHT
認定と RAA の背景
認定と RAA の背景
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
VirusTotalによる分析
サイトパフォーマンス分析
Google PageSpeed Insights — mobile performance audit of service-cloudflare.com · checked Mar 31, 2026
このサイトによって何か影響を受けましたか?
アカウント資格情報、個人情報、支払い情報を入力した場合、またはこのドメインからファイルをダウンロードした場合は、すぐに対処してください。インシデントを報告し、自分自身を守るのに役立つリソースを以下に示します。
お住まいの地域の当局へ報告してください
サイバー犯罪の公式連絡先 または 苦情草稿を作成する → を取得するには、国を選択してください。
任意のドメインを確認する
保存されたブロックリスト、WHOIS、DNS、および公開スキャン証拠を使用した脅威分析
今すぐスキャンフィッシングを報告する
不審なドメインを当社の脅威データベースに報告してください — コミュニティを守りましょう
レポートリアルタイム脅威情報フィード
最近のフィッシングレポートと観察された可用性の変化
監視最新情報を入手し、安全を確保しましょう
リアルタイムの脅威を監視するか、誤検知だと思われる場合はこのリストに異議を申し立ててください