tta-cms-web[.]pages[.]dev
Перевірка домену tta-cms-web.pages.dev на фішинг і безпеку
“Aanmelden bij uw account”
tta-cms-web.pages.dev — Останній відомий активний (HTTP 200). Уособлення бренду: Microsoft; Тип шахрайства: Crypto Scam. Зведення доказів: VirusTotal 1/91 (Forcepoint ThreatSeeker); PhishDestroy score 68/100. Реєстратор: Cloudflare.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
The domain tta-cms-web.pages.dev has been observed delivering a Microsoft‑brand impersonation campaign. The site presents a login page titled “Aanmelden bij uw account”, which mimics the language of Microsoft account authentication. The campaign is currently listed as active and its risk level is under investigation. The infrastructure is already flagged by the PhishDestroy blocklist and appears on one additional security blocklist. Technical analysis shows the domain resolves to the IP address 40.126.32.74, which belongs to the Cloudflare network (AS13335) and is geolocated in the United States. The domain is hosted behind Cloudflare’s edge service, using the nameservers sreeni.ns.cloudflare.com and yevgen.ns.cloudflare.com. TLS termination is provided by Google Trust Services under the WE1 certificate, and HTTP Strict Transport Security (HSTS) is enforced. The web server returns an HTTP 302 redirect, likely steering victims to a secondary payload host. The page’s visual design aligns with a cryptocurrency‑themed scam, as indicated by the “cryptocurrency” classification in the intelligence feed. The site carries a Gridinsoft trust score of 0 out of 100, reflecting a high confidence of malicious intent. Despite the lack of detections on VirusTotal (0/95), the low trust score and active blocklist entries suggest the domain is being used for credential harvesting. Defenders should add 40.126.32.74 and the full domain to network deny lists, monitor DNS queries for the associated Cloudflare nameservers, and enforce email filtering rules that detect the Dutch‑language login phrase “Aanmelden bij uw account”. Continuous threat‑intelligence feeds should be consulted for any new indicators, and any compromised credentials should be forced to reset. Given the active status, organizations should treat this infrastructure as a high‑priority indicator of compromise.
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Технології · 1 identified
HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 100% впевненостіАналіз VirusTotal
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога