pub-9e2030303d9b43ffaedcde988f24645c[.]r2[.]dev
“Not Found”
pub-9e2030303d9b43ffaedcde988f24645c.r2.dev — 未验证. 品牌冒充:Microsoft; 诈骗类型:Generic Phishing. 证据摘要: VirusTotal 13/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, CyRadar); URLQuery 4 alerts; URLScan malicious verdict; PhishDestroy score 89/100. 注册商: Cloudflare R2.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
The domain pub-9e2030303d9b43ffaedcde988f24645c.r2.dev is assessed as part of a generic_phishing infrastructure. No legitimate brand association or drainer kit attribution is indicated in the available intelligence. The page title resolves to "Not Found", suggesting either content removal or inactive hosting, consistent with transient phishing deployment patterns using object storage endpoints.
Technical indicators show elevated malicious reputation. VirusTotal reports 19/95 security vendors flagging the domain as malicious. The domain is registered and served through Cloudflare R2 infrastructure, with SSL provided via Let's Encrypt (E7 certificate chain). The resolved IP address is 104.18.54.45, geolocated to CA under Cloudflare, Inc. hosting. The domain appears on 2 security blocklists, and the page title observed is "Not Found", indicating no active landing content at time of inspection. No Google Safe Browsing status data is provided in the available dataset.
At present, the domain status is offline, indicating possible takedown or deactivation of the phishing content. However, infrastructure reuse risk remains elevated due to the use of distributed storage hosting and CDN-backed IP masking. Even when inactive, such domains may be rapidly reactivated or replaced within the same hosting ecosystem. Given the 19/95 detection ratio and multi-source blocklist presence, the domain should be treated as high-risk historical phishing infrastructure. Recommended handling includes continued blocklisting of the host pattern, monitoring for sibling subdomain creation under the same R2 namespace, and enforcing network-level filtering to prevent reactivation-based delivery attempts.
网络安全情报
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Cloudflare DNS | pub-9e2030303d9b43ffaedcde988f24645c.r2.dev |
malicious | Sinkholed |
| OpenDNS | pub-9e2030303d9b43ffaedcde988f24645c.r2.dev |
phishing | Phishing Block |
| DNS4EU | pub-9e2030303d9b43ffaedcde988f24645c.r2.dev |
malicious | Sinkholed |
| Quad9 DNS | pub-9e2030303d9b43ffaedcde988f24645c.r2.dev |
malicious | Sinkholed |
威胁响应 Pipeline
公共封禁名单状态
所用技术 · 2 identified
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comVirusTotal 分析
存档证据
网站性能分析
Google PageSpeed Insights — mobile performance audit of pub-9e2030303d9b43ffaedcde988f24645c.r2.dev · checked Mar 24, 2026
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。