run-gateway[.]pages[.]dev
run-gateway.pages.dev 网络钓鱼与安全检查
“CODE COMPILER”
run-gateway.pages.dev — 内容不可用 (HTTP 502). 诈骗类型:Generic Phishing. 证据摘要: VT 0/91; URLScan no malicious verdict; GSB no flag; BL 2 (MetaMask, SEAL); PD 71/100. 注册商: Cloudflare.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
run-gateway.pages.dev is a tenant hostname on Cloudflare, not a separately registered domain. PhishDestroy first recorded this hostname on Jun 26, 2026. The stored content classification is generic phishing. The assembled evidence scores 71/100 (high).
Two independent sources are positive: MetaMask and SEAL. MetaMask and SEAL listed the hostname in the external-blocklist snapshot on Aug 7, 2026 at 18:20 UTC. The evidence is not unanimous. VirusTotal recorded 0 detections among 91 engines on Jul 18, 2026 at 18:45 UTC. Google Safe Browsing returned no flag on Jun 26, 2026 at 11:16 UTC. URLScan completed without a malicious verdict (score 0) on Jun 27, 2026 at 08:13 UTC. The 0/91 VirusTotal result therefore records detection disagreement at that collection time, not the absence of the later source findings.
HTTP 502 was recorded on Aug 7, 2026 at 01:06 UTC; content was unavailable. Cloudflare is the hosting platform for this tenant, not its registrar. At collection time, the hostname resolved to 172.66.47.118 on AS13335 (CLOUDFLARENET - Cloudflare, Inc., US). The associated network metadata labels the endpoint as AS13335 Cloudflare, Inc. in San Francisco, US. This is shared platform infrastructure; the IP and ASN are hosting context, not attribution to unrelated tenants. The stored server header is cloudflare. Captured page title: “CODE COMPILER”. DOM analysis completed on Jun 26, 2026 at 14:20 UTC; stored DOM score 0/100. The evidence archive retains 2 visual captures from PhishDestroy and URLScan. IoC extraction completed on Jul 29, 2026 at 02:51 UTC; stored 0 format-validated wallet addresses and 0 Telegram indicators.
No target brand has been confirmed from stored page content; hostname wording alone is not treated as brand evidence. The 0/100 DOM score means that the DOM pass stored no scored indicators; it does not negate the independent source findings. Taken together, the page content and independent findings support classifying this hostname as generic phishing.
威胁响应 Pipeline
公共封禁名单状态
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。