pubf868e77df61146e2a31924f0f62189d5[.]r2[.]dev
pubf868e77df61146e2a31924f0f62189d5.r2.dev — 未验证. 证据摘要: VirusTotal 1/91 (alphaMountain.ai); PhishDestroy score 71/100. 注册商: Cloudflare R2.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
PhishDestroy identifies pubf868e77df61146e2a31924f0f62189d5.r2.dev as a credential phishing host designed to trick users into submitting login credentials. The domain uses a Let's Encrypt SSL certificate to appear legitimate, but security engines have not yet flagged it despite being active. This suggests the threat is still emerging and may evade detection temporarily.
This domain was flagged by PhishDestroy’s automated systems as a credential phishing site targeting login credentials. The domain resolves to a hosted storage bucket at r2.dev, a service often abused for rapid deployment of phishing pages. The SSL certificate issued by Let's Encrypt (not self-signed) indicates an attempt to appear trustworthy. VirusTotal reports 0 detections out of 95 engines as of latest scan, highlighting a window of opportunity for attackers before detection signatures mature.
If you visited pubf868e77df61146e2a31924f0f62189d5.r2.dev, immediately review any credentials entered. Change passwords on all related accounts, use two-factor authentication, and scan your device for malware. Report the domain to your organization’s security team or through PhishDestroy’s reporting tool to help block it. Avoid re-entering credentials on this domain and check for unusual activity in your accounts.
威胁响应 Pipeline
公共封禁名单状态
VirusTotal 分析
存档证据
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。