perno-galix-trima[.]pages[.]dev
“Suspected phishing site | Cloudflare”
perno-galix-trima.pages.dev — Контент недоступний. Уособлення бренду: Genericcloudflare; Тип шахрайства: Credential Phishing. Зведення доказів: VirusTotal 17/95 (ADMINUSLabs, Criminal IP, alphaMountain.ai, BitDefender, CyRadar); URLScan malicious verdict; PhishDestroy score 95/100. Реєстратор: Cloudflare.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
This domain is flagged as a credential harvesting phishing site targeting users through deceptive login interfaces. Analysis indicates the infrastructure was designed to impersonate legitimate services, likely to capture sensitive authentication details such as usernames, passwords, and multi-factor authentication codes. The risk level is classified as elevated due to its active distribution and confirmed malicious intent prior to takedown. Infrastructure analysis reveals the domain perno-galix-trima.pages.dev was registered through Cloudflare, Inc. and resolved to the IP address 188.114.97.3, associated with AS13335 (Cloudflare, Inc.) in the United States. The domain was created on November 19, 2025, and is currently offline. Security vendors on VirusTotal detected the domain, with 17 out of 95 flagging it as malicious. The SSL certificate is issued by Google Trust Services (WE1), a common attribute in phishing campaigns leveraging legitimate certificate authorities. The domain appears on two security blocklists: PhishDestroy and PhishingDB. The page title, 'Suspected phishing site | Cloudflare,' further corroborates its malicious classification. Mitigation steps for this threat include blocking the domain and its associated IP (188.114.97.3) at the network perimeter. Organizations should update endpoint protection rules to detect and prevent access to this domain and similar Cloudflare-hosted phishing pages. Security teams are advised to monitor for indicators of compromise, such as unusual login attempts or credentials submitted to this domain prior to its takedown. User awareness training should emphasize the risks of credential harvesting attacks, particularly those hosted on seemingly legitimate cloud infrastructure. If credentials were entered on this site, immediate password resets and multi-factor authentication reviews are recommended for affected accounts.
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Криміналістичні дані
Технології · 3 identified
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Аналіз VirusTotal
Архівні докази
Аналіз продуктивності сайту
Google PageSpeed Insights — mobile performance audit of perno-galix-trima.pages.dev · checked Apr 11, 2026
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога