frontend-gateway[.]pages[.]dev
“CODE COMPILER”
证据摘要
This domain, frontend-gateway.pages.dev, is currently under investigation for generic_phishing activity. Analysis indicates no direct association with known brand impersonation or drainer kits, but the naming convention ('frontend-gateway') suggests potential targeting of cloud service users or developers. The domain structure aligns with common phishing tactics designed to mimic legitimate API endpoints or gateway services, which may trick victims into entering credentials or sensitive information. Infrastructure analysis reveals the following technical indicators: the domain resolves to IP address 172.66.44.195, a Cloudflare-operated endpoint. VirusTotal reports 0 detections out of 95 engines, indicating no prior flagging at the time of this report. The domain is registered through Cloudflare, Inc., with no publicly available creation date. Google Safe Browsing (GSB) status remains unconfirmed, and no blocklist entries were identified across major threat intelligence platforms. The lack of detections does not preclude malicious intent, as the domain may still be in the early stages of deployment or evading detection through low-volume targeting. As of this report, frontend-gateway.pages.dev remains active, with no takedown or sinkholing actions observed. Response actions include continuous monitoring for changes in detection status, IP reputation shifts, or new associations with known phishing campaigns. The remaining risk is classified as under_investigation due to the absence of confirmed malicious activity but the presence of high-risk infrastructure patterns. Organizations are advised to implement DNS-based blocking for the domain and IP, monitor for unusual outbound connections to 172.66.44.195, and alert users to potential credential harvesting attempts via cloud service-themed lures. Further analysis is required to determine the scope of any associated campaigns.
Data Coverage
威胁响应 Pipeline
阻止列表覆盖
监控中的外部数据源 10 个 · 已存快照 2026年8月11日
VirusTotal 分析
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。
检查任意域名
使用存储的阻止列表、WHOIS、DNS 和公共扫描证据进行威胁分析
立即扫描举报网络钓鱼
将可疑域名提交至我们的威胁数据库——保护社区
报告实时威胁动态
最近的网络钓鱼报告和观察到的可用性变化
监控