zrfsub[.]pages[.]dev
zrfsub.pages.dev için kimlik avı ve güvenlik kontrolü
“周润发博客 - 收录开源,好用的互联网项目”
zrfsub.pages.dev — Bilinen son aktif (HTTP 200). Dolandırıcılık türü: Generic Phishing. Kanıt özeti: VirusTotal 2/91 (alphaMountain.ai, Sophos); PhishDestroy score 71/100. Kayıt kuruluşu: Cloudflare.
Özgün adli kaydı korumak için aşağıdaki ayrıntılı PhishDestroy AI analizi İngilizce bırakılmıştır.
PhishDestroy identifies zrfsub.pages.dev as an active Social Security phishing domain currently under investigation for fraudulent activity. This domain, hosted on Cloudflare Pages, is being monitored for potential impersonation of official U.S. Social Security Administration (SSA) portals. The threat remains classified as a generic phishing campaign due to unresolved verification of impersonated entities and operational intent. Users are advised to exercise caution when encountering this domain, as it may be used to harvest sensitive personal and financial information under false pretenses.
This domain was flagged by 0 of 95 VirusTotal vendors as of the latest scan, indicating a delay in detection system recognition despite its active status. It resolves to IP 172.66.47.143 via Cloudflare, Inc., with a Let's Encrypt SSL certificate for HTTPS obfuscation. The domain is part of Cloudflare's Pages platform, leveraging legitimate infrastructure to evade traditional blacklisting. No blocklist entries or trust scores are currently available, leaving users and organizations vulnerable to unchecked exposure. The lack of detections suggests a newly emerged or stealthily operated campaign relying on Cloudflare's reputation to bypass initial scrutiny.
Given the active threat status and absence of vendor detections, immediate precautionary measures are recommended. Users should avoid accessing zrfsub.pages.dev and report any instances of encountering this domain to their security teams or relevant authorities. Organizations are advised to update firewall rules and DNS blocklists to preemptively block traffic to this IP (172.66.47.143) and associated domains. Cloudflare Pages users should audit their domains for unauthorized subdomains and enable strict verification protocols. Continuous monitoring via threat intelligence feeds is critical to mitigate potential data breaches or credential harvesting attacks linked to this domain.
Ağ Güvenliği İstihbaratı
Tehdit Müdahale Pipeline
Genel Engelleme Listesi Durumu
Teknolojiler · 6 identified
JavaScript runtime built on Chrome V8 engine for server-side development.
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Advertising platform — conversion and remarketing tracking pixel.
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
VirusTotal Analizi
Site Performans Analizi
Google PageSpeed Insights — mobile performance audit of zrfsub.pages.dev · checked Mar 25, 2026
Kanıtlar ve Dış Raporlar
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin