home-exadua-us[.]pages[.]dev
“Suspected phishing site | Cloudflare”
home-exadua-us.pages.dev — İçerik kullanılamıyor. Marka kimliğine bürünme: Genericcloudflare; Dolandırıcılık türü: Credential Phishing. Kanıt özeti: VirusTotal 8/94 (ADMINUSLabs, ChainPatrol, alphaMountain.ai, Chong Lua Dao, CyRadar); URLQuery 1 alert; URLScan malicious verdict; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 79/100. Kayıt kuruluşu: Cloudflare.
Özgün adli kaydı korumak için aşağıdaki ayrıntılı PhishDestroy AI analizi İngilizce bırakılmıştır.
This domain, home-exadua-us.pages.dev, was flagged as a credential phishing site and taken offline as of July 24, 2026. Infrastructure analysis reveals it was registered on March 22, 2026, through Cloudflare, Inc., and resolved to IP 172.66.44.230, hosted on Cloudflare’s network in Canada. The SSL certificate was issued by Google Trust Services (WE1), and the site employed HSTS and HTTP/3, consistent with Cloudflare’s default security headers. At the time of assessment, the domain returned an HTTP 403 status, and the page title explicitly stated 'Suspected phishing site | Cloudflare,' indicating Cloudflare’s automated detection or manual review intervened. Eight of 94 security vendors on VirusTotal flagged the domain, and it appeared on three security blocklists, including PhishDestroy, MetaMask, and SEAL.
Gridinsoft assigned a trust score of 0/100, reinforcing its malicious classification. The domain’s nameservers (elijah.ns.cloudflare.com, nataly.ns.cloudflare.com) and registration details confirm Cloudflare as the hosting provider, which may limit visibility into the original actor’s infrastructure. No specific brand or phishing kit was identified in the available data, and the exact content of the phishing page remains unanalyzed. Defenders should treat this domain as confirmed malicious for credential phishing.
Block the domain and its resolved IP (172.66.44.230) at the perimeter. Review logs for connections to this domain or IP between March 22 and July 24, 2026, particularly for outbound HTTP/HTTPS traffic. If the domain was accessed internally, initiate credential reset protocols for affected accounts. Monitor for similar domains using the 'exadua' substring or Cloudflare Pages subdomains with recent creation dates, as this pattern may indicate follow-up campaigns.
Ağ Güvenliği İstihbaratı
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Quad9 DNS | home-exadua-us.pages.dev |
malicious | Sinkholed |
Tehdit Müdahale Pipeline
Genel Engelleme Listesi Durumu
Teknolojiler · 3 identified
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
VirusTotal Analizi
Site Performans Analizi
Google PageSpeed Insights — mobile performance audit of home-exadua-us.pages.dev · checked Mar 21, 2026
Kanıtlar ve Dış Raporlar
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin