MALICIOUS — CRITICAL
restoreweb.pages.dev için kimlik avı ve güvenlik kontrolü
restoreweb[.]
Analysis of the domain restoreweb.pages.dev, conducted on July 25, 2026, reveals that it was involved in a credential phishing campaign.
- VirusTotal
- 6/94
- Blocklists
- No stored match
- Kullanılabilirlik
- Ulaşılabilir · erişim kısıtlı · HTTP 403
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
restoreweb.pages.dev — Ulaşılabilir · erişim kısıtlı (HTTP 403). Dolandırıcılık türü: Credential Phishing. Kanıt özeti: VirusTotal 6/94 (ADMINUSLabs, alphaMountain.ai, CyRadar, ESET, Fortinet); PhishDestroy score 73/100. Kayıt kuruluşu: Cloudflare.
Özgün adli kaydı korumak için aşağıdaki ayrıntılı PhishDestroy AI analizi İngilizce bırakılmıştır.
Evidence Analysis
Analysis of the domain restoreweb.pages.dev, conducted on July 25, 2026, reveals that it was involved in a credential phishing campaign. The domain was registered through Cloudflare, Inc. and created on March 24, 2026. The domain title, 'Fixes and Support for Crypto and Service Issues,' suggests that the site was designed to mimic a legitimate support page for cryptocurrency or related services. This domain is currently offline, resolving to the IP address 172.66.44.147, which is located in California, USA, and hosted by Cloudflare, Inc. The HTTP status code 403 indicates that access to the site is forbidden, which is consistent with the domain being taken offline.
The SSL certificate is issued by Google Trust Services, a WE1 certificate, which may have been used to enhance the site's credibility. The domain is flagged by PhishDestroy and has a Gridinsoft trust score of 0/100, indicating a high level of risk. The presence of HSTS and HTTP/3 technologies further suggests that the operators aimed to provide a secure and modern web experience to their targets, potentially to gain their trust.
While the exact content of the site has not been analyzed, the page title and the nature of the domain suggest that it was likely used to phish credentials from users seeking support for cryptocurrency or service issues. Defenders should be vigilant and block this domain in their security systems to prevent any potential phishing attacks. The domain's current offline status is a positive indicator, but it should still be monitored for any signs of reactivation.
Stored source results
Recorded verdicts and infrastructure observations for this domain.
Veri kapsamı12 recorded checks
Ağ Güvenliği İstihbaratı
Tehdit Müdahale Pipeline
Genel Engelleme Listesi Durumu
Adli İstihbarat
Teknolojiler · 3 identified
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
VirusTotal Analizi
Site Performans Analizi
Google PageSpeed Insights — mobile performance audit of restoreweb.pages.dev · checked Mar 24, 2026
Kanıtlar ve Dış RaporlarIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.