curve-lp-analyzer-45y[.]pages[.]dev
“React App”
curve-lp-analyzer-45y.pages.dev — Conteúdo indisponível. Representação da marca: Curve; Tipo de golpe: Crypto Scam. Resumo das evidências: VirusTotal 12/93 (ADMINUSLabs, ChainPatrol, alphaMountain.ai, BitDefender, CyRadar); Google Safe Browsing flagged; PhishDestroy score 86/100. Registrador: Cloudflare.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
Analysis of curve-lp-analyzer-45y.pages.dev, observed as a high‑risk brand‑impersonation vector targeting Curve, indicates that the domain is currently offline but retains a persistent threat footprint. The domain resolves to 172.66.47.104, an address owned by AS13335 Cloudflare, Inc. in the United States. Registration was performed through Cloudflare, Inc., and the authoritative name servers listed are adi.ns.cloudflare.com, karl.ns.cloudflare.com, odin.ns.cloudflare.com, and rose.ns.cloudflare.com. The site presented a HTTP 403 response and served a page titled “React App”, suggesting a generic front‑end rather than a fully‑rendered phishing page at the time of capture. SSL is provided by Google Trust Services under the WE1 certificate, confirming TLS termination at Cloudflare’s edge.
Security telemetry shows that 12 of 93 VirusTotal scanners flagged the domain, and Google Safe Browsing classifies it as a social‑engineering threat. The domain appears on a single public blocklist and has been flagged by PhishDestroy. Additional technical indicators include enforced HSTS, Cloudflare’s edge services, and support for HTTP/3. Gridinsoft assigned a trust score of 0 / 100, reinforcing the malicious assessment.
The domain creation date of 02 September 2020 demonstrates a long‑standing infrastructure that may be reused across campaigns. While the exact payload or credential‑harvesting mechanisms have not been publicly disclosed, the combination of brand impersonation, crypto‑scam classification, and multiple vendor detections warrants immediate containment. Defenders should block the host IP and all associated Cloudflare name servers, add the domain to local deny lists, and monitor for any resurgence of activity. Continuous re‑scanning with multi‑vendor engines is recommended to capture any changes in the threat profile, and any future HTTP 200 responses should be examined for credential‑capture forms or malicious scripts.
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Tecnologias · 3 identified
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Análise do VirusTotal
Evidências arquivadas
Análise de desempenho do site
Google PageSpeed Insights — mobile performance audit of curve-lp-analyzer-45y.pages.dev · checked Apr 24, 2026
Evidências e relatórios externos
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo