start-eng-trezr[.]pages[.]dev
“Suspected phishing site | Cloudflare”
Kaydedilmiş gözlem
Gözlemlenen başlık farkı
Kanıt özeti
This domain, start-eng-trezr.pages.dev, is confirmed as a credential theft phishing operation. Analysis indicates the site was designed to harvest user login credentials through deceptive login portals, likely mimicking legitimate authentication flows. No specific brand impersonation or cryptocurrency drainer kit signatures were identified in initial triage, though the credential harvesting mechanism aligns with common phishing toolkits observed in enterprise-targeted campaigns. The domain infrastructure leverages Cloudflare hosting, a tactic frequently employed to obfuscate origin servers and evade detection. Technical indicators reveal the domain was registered on August 11, 2025, through Cloudflare, Inc., and resolves to the IP address 172.66.45.18, associated with AS13335 (Cloudflare, Inc.) in the United States. VirusTotal detection metrics show 17 out of 95 security vendors flagging the domain as malicious, while it appears on 2 distinct security blocklists. The SSL certificate is issued by Google Trust Services (WE1), a common certificate authority for both legitimate and malicious domains. No Google Safe Browsing (GSB) hits were reported at the time of analysis, though this may reflect a lag in GSB's detection pipeline rather than benign status. The domain is currently offline, with the page title explicitly stating 'Suspected phishing site | Cloudflare,' suggesting takedown or suspension by the hosting provider. Despite its offline status, residual risk remains for users who may have interacted with the domain prior to deactivation. Organizations are advised to block the domain and IP at perimeter defenses, conduct retrospective log analysis for connections to 172.66.45.18, and monitor for credential reuse if any exposure occurred. The rapid creation-to-takedown timeline (under 48 hours) indicates a likely disposable infrastructure pattern, common in credential theft campaigns.
Data Coverage
Ağ Güvenliği İstihbaratı
Tehdit Müdahale Pipeline
Engelleme listesi kapsamı
10 izlenen harici kaynak · kayıtlı anlık görüntü 12.08.2026
Tespit zaman çizelgesi
-
Cloudflare Radar
Cloudflare Radar taraması kaydedildi · Taramayı aç
-
Alan adı durumu
Erişilebilir → Erişilemiyor
-
Cloudflare Radar
Cloudflare Radar taraması kaydedildi · Taramayı aç
Teknolojiler
3 yüksek güvenli teknoloji belirlendi
VirusTotal Analizi
Site Performans Analizi
Google PageSpeed Insights — mobile performance audit of start-eng-trezr.pages.dev · checked Apr 13, 2026
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin