geode-jaguar-5366[.]typedream[.]app
“OneDrive”
geode-jaguar-5366.typedream.app — Контент недоступен. Олицетворение бренда: Onedrive. Сводка доказательств: VirusTotal 16/95 (ADMINUSLabs, alphaMountain.ai, BitDefender, CRDF, CyRadar); CF Radar malicious; PhishDestroy score 95/100. Регистратор: Cloudflare.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
This domain, geode-jaguar-5366.typedream.app, was observed hosting a brand‑impersonation page that mimics OneDrive, as indicated by the page title “OneDrive”. The site is currently offline and returns HTTP 403, which prevents content retrieval but confirms the host is still reachable. Infrastructure analysis shows the domain resolves to IP 188.114.96.3, an address owned by AS13335 Cloudflare, Inc., located in the United States. Registration was performed through Cloudflare, Inc., and the TLS certificate is issued by Google Trust Services under the WE1 label, suggesting use of Google’s managed PKI. The server stack reports Node.js, React, Next.js, Google Cloud services (Trace and CDN), Cloudflare, and Webpack, a typical combination for modern web applications and consistent with many phishing kits.
VirusTotal scans flagged the domain in 16 of 95 engines, and the domain appears on a single blocklist operated by PhishDestroy. No additional blocklists or safe‑browsing detections were reported. The lack of nameserver information (NS_NOT_FOUND) limits deeper DNS‑level attribution. The limited detection footprint—one blocklist entry and modest vendor consensus—means the site may have been short‑lived or quickly taken down.
Defenders should continue to monitor the IP 188.114.96.3 for related activity, enforce existing blocklist entries, and consider adding the domain to internal deny lists. Because the domain leverages reputable cloud infrastructure, threat actors can rapidly spin up similar impersonation pages; therefore, security controls that inspect outbound requests for OneDrive‑related URLs remain advisable. Analysts should also track future registrations under the typedream.app sub‑domain space, as the pattern of using typedream.app for brand‑impersonation has been observed elsewhere. Until the site is permanently removed, the elevated risk rating reflects the confirmed brand impersonation and the presence of multiple detection sources.
Данные сетевой безопасности
Процесс реагирования на угрозы
Статус в публичных блок-листах
Технологии · 9 identified
Node.js is an open-source, cross-platform, JavaScript runtime environment that executes JavaScript code outside a web browser.
nodejs.org 100% уверенностиReact is an open-source JavaScript library for building user interfaces or UI components.
reactjs.org 100% уверенностиNext.js is a React framework for developing single page Javascript applications.
nextjs.org 100% уверенностиGoogle Cloud Trace is a distributed tracing system that collects latency data from applications and displays it in the Google Cloud Console.
cloud.google.com 100% уверенностиCloud CDN uses Google's global edge network to serve content closer to users.
cloud.google.com 100% уверенностиCloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100% уверенностиHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% уверенностиАнализ VirusTotal
Архивные доказательства
Анализ производительности сайта
Google PageSpeed Insights — mobile performance audit of geode-jaguar-5366.typedream.app · checked Apr 23, 2026
Доказательства и внешние отчеты
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание