zrfsub[.]pages[.]dev
zrfsub.pages.dev 피싱 및 보안 점검
“周润发博客 - 收录开源,好用的互联网项目”
zrfsub.pages.dev — 마지막으로 알려진 활성 (HTTP 200). 사기 유형: Generic Phishing. 증거 요약: VirusTotal 2/91 (alphaMountain.ai, Sophos); PhishDestroy score 71/100. 등록기관: Cloudflare.
원본 포렌식 기록을 보존하기 위해 아래의 상세 PhishDestroy AI 분석은 영어로 유지됩니다.
PhishDestroy identifies zrfsub.pages.dev as an active Social Security phishing domain currently under investigation for fraudulent activity. This domain, hosted on Cloudflare Pages, is being monitored for potential impersonation of official U.S. Social Security Administration (SSA) portals. The threat remains classified as a generic phishing campaign due to unresolved verification of impersonated entities and operational intent. Users are advised to exercise caution when encountering this domain, as it may be used to harvest sensitive personal and financial information under false pretenses.
This domain was flagged by 0 of 95 VirusTotal vendors as of the latest scan, indicating a delay in detection system recognition despite its active status. It resolves to IP 172.66.47.143 via Cloudflare, Inc., with a Let's Encrypt SSL certificate for HTTPS obfuscation. The domain is part of Cloudflare's Pages platform, leveraging legitimate infrastructure to evade traditional blacklisting. No blocklist entries or trust scores are currently available, leaving users and organizations vulnerable to unchecked exposure. The lack of detections suggests a newly emerged or stealthily operated campaign relying on Cloudflare's reputation to bypass initial scrutiny.
Given the active threat status and absence of vendor detections, immediate precautionary measures are recommended. Users should avoid accessing zrfsub.pages.dev and report any instances of encountering this domain to their security teams or relevant authorities. Organizations are advised to update firewall rules and DNS blocklists to preemptively block traffic to this IP (172.66.47.143) and associated domains. Cloudflare Pages users should audit their domains for unauthorized subdomains and enable strict verification protocols. Continuous monitoring via threat intelligence feeds is critical to mitigate potential data breaches or credential harvesting attacks linked to this domain.
네트워크 보안 인텔리전스
위협 대응 Pipeline
공개 차단 목록 상태
사용 기술 · 6 identified
JavaScript runtime built on Chrome V8 engine for server-side development.
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Advertising platform — conversion and remarketing tracking pixel.
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
VirusTotal 분석
사이트 성능 분석
Google PageSpeed Insights — mobile performance audit of zrfsub.pages.dev · checked Mar 25, 2026
증거 및 외부 보고서
이 사이트로 인해 영향을 받으셨나요?
계정 자격 증명, 개인 정보 또는 결제 정보를 입력했거나 이 도메인에서 파일을 다운로드한 경우 즉시 조치를 취하세요. 다음은 사건을 신고하고 자신을 보호하는 데 도움이 되는 리소스입니다.
지역 당국에 신고하십시오
공식 사이버 범죄 연락처 또는 불만사항 초안 작성 →를 받으려면 국가를 선택하세요.