webed-cloud-upxold-loxic[.]pages[.]dev
“Suspected phishing site | Cloudflare”
webed-cloud-upxold-loxic.pages.dev — Conteúdo indisponível. Representação da marca: Genericcloudflare; Tipo de golpe: Credential Phishing. Resumo das evidências: VirusTotal 12/93 (ADMINUSLabs, alphaMountain.ai, BitDefender, CyRadar, Fortinet); URLScan malicious verdict; Google Safe Browsing flagged; PhishDestroy score 91/100. Registrador: Cloudflare.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
This domain, webed-cloud-upxold-loxic.pages.dev, is identified as a high-risk generic phishing site designed to harvest user credentials through fraudulent authentication portals. Analysis indicates the infrastructure mimics legitimate Cloudflare login pages, likely leveraging a pre-built phishing kit to automate credential theft. While no specific drainer kit is confirmed, the domain's design and structure align with common phishing toolkits used to target enterprise and individual users under the guise of cloud service authentication. Infrastructure analysis reveals the following technical indicators: the domain is flagged by 12 out of 95 security vendors on VirusTotal, registered through Cloudflare, Inc., and resolves to the IP address 172.66.44.108, hosted on AS13335 (Cloudflare, Inc.) in the United States. The domain was created on November 05, 2025, and is currently blocked by Google Safe Browsing for phishing activity. Additionally, it appears on one security blocklist, and its SSL certificate is issued by Google Trust Services (WE1), a common certificate authority for both legitimate and malicious domains. The domain is currently offline, likely due to takedown actions by the hosting provider or security teams. However, residual risk persists as threat actors may re-deploy the phishing kit under a new domain or subdomain. Users who interacted with this site should immediately reset credentials for any accounts accessed during the exposure window, particularly those tied to cloud services or enterprise authentication portals. Organizations are advised to monitor for unauthorized access attempts and implement multi-factor authentication to mitigate credential-based attacks. Continuous vigilance is recommended, as phishing campaigns often recycle infrastructure or tactics.
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Análise do VirusTotal
Análise de desempenho do site
Google PageSpeed Insights — mobile performance audit of webed-cloud-upxold-loxic.pages.dev · checked Apr 21, 2026
Evidências e relatórios externos
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo