rpchubfix[.]pages[.]dev
Проверка домена rpchubfix.pages.dev на фишинг и безопасность
“RPC Recovery Hub - We are here to help you resolve your crypto related issues”
rpchubfix.pages.dev — Доступен · доступ ограничен (HTTP 403). Тип мошенничества: Credential Phishing. Сводка доказательств: VirusTotal 5/93 (ChainPatrol, alphaMountain.ai, CyRadar, Forcepoint ThreatSeeker, Fortinet); 4 external blocklist matches; PhishDestroy score 82/100. Регистратор: Cloudflare.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
The domain rpchubfix.pages.dev is flagged as a credential‑phishing site targeting cryptocurrency users. Infrastructure analysis shows the domain was registered on February 21, 2026 through Cloudflare, Inc., and resolves to the IP address 188.114.96.3, which belongs to AS13335 Cloudflare, Inc. in the United States. DNS is served by Cloudflare’s authoritative name servers max.ns.cloudflare.com and norah.ns.cloudflare.com, indicating the operator is leveraging Cloudflare’s CDN and protection services. The site presents a valid SSL certificate issued by Google Trust Services / WE1, confirming that TLS termination is performed by Cloudflare’s edge.
HTTP headers reveal the use of HSTS and HTTP/3, both typical of modern Cloudflare‑hosted sites. An HTTP request returns a 403 status, and the domain is currently taken offline, which limits direct content inspection. The page title “RPC Recovery Hub – We are here to help you resolve your crypto related issues” aligns with the credential‑phishing classification and suggests a social‑engineering lure aimed at crypto‑wallet owners. Threat intelligence indicates the domain appears on five security blocklists (PhishDestroy, ScamSniffer, Polkadot, Enkrypt, Codeesura) and has been flagged by five of ninety‑three VirusTotal scanners, reinforcing the malicious assessment.
Gridinsoft assigns a trust score of 0 / 100, reflecting a high confidence of abuse. While the 403 response prevents verification of any malicious payload or credential‑harvesting form, the combination of blocklist listings, low trust score, and the targeted page title provides concrete evidence of phishing intent. Defenders should immediately block rpchubfix.pages.dev at the DNS and proxy layers, add the domain to web‑filter allowlists as a malicious entry, and monitor for any future re‑hosting of the same content on alternative IPs or subdomains.
Процесс реагирования на угрозы
Статус в публичных блок-листах
Технологии · 3 identified
HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 100% уверенностиCloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100% уверенностиHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% уверенностиАнализ VirusTotal
Анализ производительности сайта
Google PageSpeed Insights — mobile performance audit of rpchubfix.pages.dev · checked Apr 11, 2026
Доказательства и внешние отчеты
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание