pub-223719251411456dae7d3253c35184c9[.]r2[.]dev
“Forbidden”
pub-223719251411456dae7d3253c35184c9.r2.dev — Doğrulanmamış. Marka kimliğine bürünme: Microsoft; Dolandırıcılık türü: Generic Phishing. Kanıt özeti: VirusTotal 10/91 (alphaMountain.ai, Chong Lua Dao, CyRadar, ESET, Forcepoint ThreatSeeker); URLQuery 3 alerts; URLScan malicious verdict; PhishDestroy score 88/100. Kayıt kuruluşu: Cloudflare R2.
Özgün adli kaydı korumak için aşağıdaki ayrıntılı PhishDestroy AI analizi İngilizce bırakılmıştır.
pub-223719251411456dae7d3253c35184c9.r2.dev is currently listed as a high‑risk generic phishing site. The domain was registered on 2026‑04‑04 and is hosted behind Cloudflare R2, using a Let’s Encrypt certificate (E7) and resolving to IP 104.18.50.34, which maps to Cloudflare, Inc. in Canada. HTTP requests return a 403 status and the page title is “Forbidden”, indicating that the content is not publicly served. The domain appears on two public blocklists and has been blocked by PhishDestroy and PhishingDB. VirusTotal scans show 15 of 94 security vendors flag the domain as malicious, and Gridinsoft assigns a trust score of 0/100. The infrastructure suggests a typical abuse setup: a freshly created sub‑domain under the r2.dev namespace, leveraging Cloudflare’s edge network to obscure origin. No additional payload or phishing page content has been observed, and the exact target brand or lure remains unknown. Defenders should continue to block the domain at perimeter devices, update DNS blocklists with the provided IP and domain, and monitor for any new sub‑domains under the same r2.dev namespace. Additional analysis of any retrieved content should be performed if the site becomes reachable, and incident response teams should treat any credentials submitted to this domain as compromised.
Ağ Güvenliği İstihbaratı
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Cloudflare DNS | pub-223719251411456dae7d3253c35184c9.r2.dev |
malicious | Sinkholed |
| OpenDNS | pub-223719251411456dae7d3253c35184c9.r2.dev |
phishing | Phishing Block |
| DNS4EU | pub-223719251411456dae7d3253c35184c9.r2.dev |
malicious | Sinkholed |
Tehdit Müdahale Pipeline
Genel Engelleme Listesi Durumu
VirusTotal Analizi
Site Performans Analizi
Google PageSpeed Insights — mobile performance audit of pub-223719251411456dae7d3253c35184c9.r2.dev · checked Apr 4, 2026
Kanıtlar ve Dış Raporlar
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin