proposal-uni[.]pages[.]dev
“522: Connection timed out”
Resumo das evidências
This domain, proposal-uni.pages.dev, is flagged as a high-risk generic phishing endpoint operating under Cloudflare's infrastructure. Analysis indicates the domain was registered on March 22, 2026, and currently resolves to the IP address 172.66.44.162, located in Canada and associated with Cloudflare, Inc. The domain appears on four security blocklists, including PhishDestroy, MetaMask, ScamSniffer, and SEAL, and is classified as malicious by 14 out of 95 security vendors on VirusTotal. The site returns an HTTP 200 status code, though the page title displays a '522: Connection timed out' error, which may indicate intermittent availability or deliberate evasion tactics. Infrastructure analysis reveals the use of Cloudflare nameservers (johnny.ns.cloudflare.com and macy.ns.cloudflare.com) and technologies such as HSTS and HTTP/3, suggesting an attempt to mimic legitimate services. The SSL certificate is issued by Let's Encrypt, a common choice for both benign and malicious domains. While the domain is registered through Cloudflare, the hosting provider's role in content delivery complicates attribution, as the platform is frequently abused for phishing due to its accessibility and built-in security features. The domain's low trust scores—0/100 from Gridinsoft and 1/100 from Scamadviser—further corroborate its malicious classification. However, the exact nature of the phishing campaign remains unclear due to the generic '522' error page, which may obscure the intended payload or target. Defenders should treat this domain as actively hostile and prioritize blocking it at the network and endpoint levels. Monitoring for related subdomains or IP shifts is recommended, as threat actors often rotate infrastructure to evade detection. Given the domain's recent registration and persistent blocklist presence, it is likely part of an ongoing phishing operation rather than a compromised legitimate site.
Data Coverage
Inteligência de segurança de rede
Pipeline de resposta a ameaças
Cobertura de listas de bloqueio
10 fontes externas monitoradas · instantâneo de 11/08/2026
7 fontes externas monitoradas Sem correspondência
Linha do tempo de detecção
-
VirusTotal
0 → 8
Análise do VirusTotal
Análise de desempenho do site
Google PageSpeed Insights — mobile performance audit of proposal-uni.pages.dev · checked Mar 20, 2026
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo