uphod-login[.]pages[.]dev
“Suspected phishing site | Cloudflare”
Observação armazenada
Contraste de títulos observado
Resumo das evidências
Analysis of the domain uphod-login.pages.dev, created on February 21, 2026, indicates a high‑risk credential phishing operation. The site was served through Cloudflare’s network (AS13335) and resolved to the IP address 172.66.47.177 located in the United States. HTTP responses returned a 403 status code, and the page title reported by the server is “Suspected phishing site | Cloudflare”, confirming that the content is flagged by the provider. The TLS certificate is issued by Google Trust Services under the WE1 root, which is typical for Cloudflare‑protected sites and does not provide assurance of legitimacy.
Security‑vendor scans on VirusTotal show that 11 of 93 scanners flagged the domain, and the domain appears on a single external blocklist. Google Safe Browsing classifies the URL as social engineering, and the PhishDestroy blocklist has already taken the site offline. Reputation services assign extremely low trust scores, with Scamadviser reporting 1/100 and Gridinsoft 0/100, reinforcing the malicious assessment. The registrar information lists Cloudflare, Inc. as the registrar, and the authoritative nameservers are sunny.ns.cloudflare.com and anirban.ns.cloudflare.com, both belonging to Cloudflare’s DNS infrastructure.
Detected technologies include HSTS, Cloudflare’s edge services, and HTTP/3, all of which are consistent with a standard Cloudflare deployment. No additional indicators such as malware payloads, credential‑harvesting scripts, or target brand references were observed in the available data, leaving the precise phishing kit unknown. Defenders should block the domain at the DNS and proxy layers, add the IP address 172.66.47.177 to network‑level deny lists, and monitor for any related subdomains that resolve to the same Cloudflare infrastructure. Continuous re‑scanning of the domain and its associated IP is recommended to capture any future changes in detection status or additional malicious activity.
Data Coverage
Pipeline de resposta a ameaças
Cobertura de listas de bloqueio
10 fontes externas monitoradas · instantâneo de 12/08/2026
10 fontes externas monitoradas Sem correspondência
Linha do tempo de detecção
-
Cloudflare Radar
Varredura do Cloudflare Radar armazenada · Abrir varredura
-
Status do domínio
Acessível → Inacessível
-
Cloudflare Radar
Varredura do Cloudflare Radar armazenada · Abrir varredura
Inteligência forense
Tecnologias
3 tecnologias identificadas com alta confiança
Análise do VirusTotal
Análise de desempenho do site
Google PageSpeed Insights — mobile performance audit of uphod-login.pages.dev · checked Apr 13, 2026
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo