marsmarket[.]pro
“Checking your browser before accessing. Just a moment...”
Kanıt özeti
PhishDestroy identifies marsmarket.pro as a credential theft site designed to harvest Cloudflare login credentials. The domain displayed a fake Cloudflare verification page titled 'Checking your browser before accessing. Just a moment...' to trick visitors into entering their credentials. This threat is part of a broader campaign targeting users of Cloudflare services, with the stolen information likely used for further phishing attacks or account takeovers.
Technical analysis reveals that the domain was created on June 8, 2026, through Dynadot Inc, and resolves to IP 92.113.23.62. Its SSL certificate is issued by Let's Encrypt (R12), which is common for phishing sites due to its free and automated issuance. VirusTotal data shows that 4 out of 95 security vendors flagged this domain as malicious, and it appears on 1 security blocklist. Additionally, AlienVault OTX recorded the domain in 4 threat intelligence pulses, indicating active monitoring by the security community. The domain is now offline, but its short lifespan and rapid takedown suggest it was used aggressively.
If users visited marsmarket.pro and entered any credentials, they should immediately change their Cloudflare passwords and enable two-factor authentication. They should also monitor their accounts for suspicious activity and consider reporting the incident to Cloudflare support. PhishDestroy recommends running a full security scan on any device that accessed the site to check for malware or unauthorized access. Staying vigilant against fake verification pages is crucial, as cybercriminals increasingly use such tactics to bypass security measures.
Data Coverage
Tehdit Müdahale Pipeline
Engelleme listesi kapsamı
10 izlenen harici kaynak · kayıtlı anlık görüntü 12.08.2026
Tespit zaman çizelgesi
-
Cloudflare Radar
Cloudflare Radar taraması kaydedildi · Taramayı aç
Etki Alanı Analizi
Teknik ayrıntılarDNS, TLS adları ve zaman damgaları
ICANN OVERSIGHT
Akreditasyon ve RAA bağlamı
Akreditasyon ve RAA bağlamı
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Teknolojiler
2 yüksek güvenli teknoloji belirlendi
VirusTotal Analizi
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin