ddgghb[.]pages[.]dev
Проверка домена ddgghb.pages.dev на фишинг и безопасность
“Ton Minter”
ddgghb.pages.dev — Последний известный активный (HTTP 200). Олицетворение бренда: Foundation; Тип мошенничества: Wallet/seed Phishing. Сводка доказательств: VT 3/91 (alphaMountain.ai, Emsisoft, Gridinsoft); URLQuery 0; URLScan no malicious verdict; GSB no flag; BL 2 (ScamSniffer, Enkrypt); PD 86/100. Регистратор: Cloudflare.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
This report documents the active malicious infrastructure hosted at ddgghb.pages.dev. The domain was created on July 01 2024 through Cloudflare, Inc. and resolves to the IP address 172.66.45.20, which belongs to AS13335 (Cloudflare) located in the United States. HTTP requests return a 200 status code and the page presents the title “Ton Minter”, while the site explicitly impersonates the foundation brand. The risk rating is high and the unique seed identifier is 1dbc7e. The underlying web stack is fully provisioned by Cloudflare. Authoritative name servers are howard.ns.cloudflare.com and sloan.ns.cloudflare.com, and the TLS certificate is issued by Google Trust Services under the WE1 label, enforcing HSTS and HTTP/3. Front‑end libraries detected include SweetAlert2, jsDelivr, cdnjs, and Google Analytics, together with Cloudflare Browser Insights. These components are commonly observed in credential‑harvesting kits that present deceptive dialogs to lure victims. VirusTotal analysis shows that only one of ninety‑five security vendors flagged the domain, indicating limited detection coverage. Reputation services assign extremely low trust scores (Scamadviser 1/100, Gridinsoft 0/100), and the domain is already listed on three public blocklists, including PhishDestroy, ScamSniffer, and Enkrypt. The page title “Ton Minter” aligns with a cryptocurrency‑minting scam narrative, suggesting the actors aim to trick donors or supporters of the foundation into sending digital assets. Defenders should treat ddgghb.pages.dev as a high‑confidence malicious indicator. Immediate actions include adding the fully qualified domain to URL filtering and DNS sinkhole policies, monitoring for additional pages.dev subdomains that exhibit similar technology fingerprints, and alerting end‑users about the fake foundation impersonation. Continuous intelligence gathering is recommended to capture any evolution of the site’s content or the introduction of payloads.
Процесс реагирования на угрозы
Статус в публичных блок-листах
Технологии · 8 identified
SweetAlert2 is a JavaScript library that provides customisable, visually appealing, and responsive alert and modal dialog boxes for web applications.
sweetalert2.github.io 100% уверенностиJSDelivr is a free public CDN for open-source projects. It can serve web files directly from the npm registry and GitHub repositories without any configuration.
www.jsdelivr.com 100% уверенностиHTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 100% уверенностиGoogle Analytics is a free web analytics service that tracks and reports website traffic.
google.com 100% уверенностиCloudflare Browser Insights is a tool that measures the performance of websites from the perspective of users.
www.cloudflare.com 100% уверенностиCloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100% уверенностиHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% уверенностиАнализ VirusTotal
Анализ производительности сайта
Google PageSpeed Insights — mobile performance audit of ddgghb.pages.dev · checked Mar 27, 2026
Доказательства и внешние отчеты
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Об этом отчете: ddgghb.pages.dev
В этом отчете представлены последние сохраненные доказательства, доступные PhishDestroy. Временные метки источника отображаются там, где они доступны; Вердикты о доступности и поставщика могут измениться после сбора.
Захваченный сайт отображал заголовок страницы “Ton Minter” и мог выдавать себя за Foundation.
Начиная с 07.08.2026, ddgghb.pages.dev обнаруживался механизмами безопасности 3.
Если вы считаете, что это объявление неточно, подать апелляцию. Чтобы узнать о нашей методологии, посетите Страница часто задаваемых вопросов.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание