tuesdayfirst[.]pages[.]dev
“Webmail Login | IONOS by 1&1”
Resumo das evidências
Analysis of tuesdayfirst.pages.dev indicates that the domain was registered on March 01, 2026 and is currently taken offline, as confirmed by the blocklist entry from PhishDestroy. The site presented the page title "Webmail Login | IONOS by 1&1," which aligns with the classified scam type of brand impersonation targeting the IONOS webmail service. Infrastructure inspection shows the domain resolves to the IP address 188.114.96.3, hosted within the United States under ASN 13335 (Cloudflare, Inc.). The domain is served through Cloudflare's network, employing HSTS and HTTP/3, and utilizes a Google Trust Services / WE1 SSL certificate, suggesting a valid TLS configuration despite malicious intent.
DNS records list four Cloudflare nameservers (adi.ns.cloudflare.com, damon.ns.cloudflare.com, karl.ns.cloudflare.com, wally.ns.cl). An HTTP request to the host returns a 404 status, indicating the landing page is no longer accessible, which is consistent with the offline status. VirusTotal analysis recorded 16 detections out of 93 security vendors, reinforcing the malicious classification. The domain appears on a single external security blocklist, further confirming its threat profile.
While the page content cannot be examined directly, the combination of brand‑specific page title, registered hosting details, and multiple vendor detections provides sufficient evidence for defensive actions. Security teams should continue to block the domain at perimeter devices, update URL filtering lists, and consider sinkholing the associated IP range to prevent accidental resolution. Continuous monitoring of Cloudflare‑registered sub‑domains and related IP addresses is advised, as threat actors frequently recycle infrastructure. The limited public visibility of the site underscores the importance of proactive threat‑intel sharing to mitigate similar brand‑impersonation campaigns.
Data Coverage
Inteligência de segurança de rede
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Cloudflare DNS | tuesdayfirst.pages.dev |
malicious | Sinkholed |
| DNS4EU | tuesdayfirst.pages.dev |
malicious | Sinkholed |
Pipeline de resposta a ameaças
Cobertura de listas de bloqueio
10 fontes externas monitoradas · instantâneo de 11/08/2026
10 fontes externas monitoradas Sem correspondência
Linha do tempo de detecção
-
VirusTotal
0 → 14
-
Cloudflare Radar
Varredura do Cloudflare Radar armazenada · Abrir varredura
-
Status do domínio
Acessível → Inacessível
-
Cloudflare Radar
Varredura do Cloudflare Radar armazenada · Abrir varredura
Tecnologias
3 tecnologias identificadas com alta confiança
Análise do VirusTotal
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo