9f088313[.]ripsyr[.]pages[.]dev
“Suspected phishing site | Cloudflare”
9f088313.ripsyr.pages.dev — 可达 · 访问受限 (HTTP 403). 诈骗类型:Credential Phishing. 证据摘要: VirusTotal 12/93 (ADMINUSLabs, BitDefender, CyRadar, ESET, Fortinet); Google Safe Browsing flagged; PhishDestroy score 86/100. 注册商: Cloudflare.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
This domain, 9f088313.ripsyr.pages.dev, is identified as a generic phishing site currently marked offline. Analysis indicates the infrastructure was utilized for broad credential harvesting or fraudulent activity, though no specific brand impersonation has been confirmed. The domain exhibits characteristics consistent with opportunistic phishing campaigns targeting users through deceptive landing pages or redirects. Infrastructure analysis reveals the domain was registered through Cloudflare, Inc. and resolves to the IP address 172.66.47.147, located within the United States under AS13335 (Cloudflare, Inc.). The domain was created on September 02, 2020, and is flagged by 12 of 95 security vendors on VirusTotal. It appears on one security blocklist and is currently blocked by PhishDestroy. The SSL certificate is issued by Google Trust Services (WE1), a common provider for both legitimate and malicious domains. Google Safe Browsing has explicitly flagged this domain for phishing activity, and the page title, Suspected phishing site | Cloudflare, further corroborates its malicious classification. The domain is currently offline, reducing immediate risk to end users. However, historical activity and infrastructure reuse remain a concern. Organizations are advised to block the domain and its associated IP (172.66.47.147) at the perimeter level. Security teams should monitor for related subdomains or newly registered domains under the same registrar, particularly those leveraging Cloudflare Pages or similar hosting services. Endpoint protection solutions should be updated to include this domain in deny lists, and user awareness training should emphasize the risks of interacting with unsolicited links, even if hosted on seemingly legitimate platforms.
威胁响应 Pipeline
公共封禁名单状态
取证情报
所用技术 · 3 identified
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
VirusTotal 分析
存档证据
网站性能分析
Google PageSpeed Insights — mobile performance audit of 9f088313.ripsyr.pages.dev · checked Apr 11, 2026
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。