twt-dkptfz5p[.]pages[.]dev
“Get Your Rewards!”
twt-dkptfz5p.pages.dev — 内容不可用. 品牌冒充:["trustwallet"]. 证据摘要: VirusTotal 0/93; URLQuery 1 alert; PhishDestroy score 45/100. 注册商: Cloudflare.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
The domain twt-dkptfz5p.pages.dev was registered on February 21, 2026 through Cloudflare, Inc. and resolves to the IP address 172.66.47.95, which belongs to Cloudflare’s AS13335 network in the United States. The site was observed with the page title “Get Your Rewards!” and did not present an SSL certificate at the time of analysis. It has been taken offline, and its current HTTP status is unavailable.
Threat intelligence sources indicate that the domain appears on a single security blocklist and is actively blocked by the PhishDestroy service. VirusTotal records show that the domain was scanned by 93 antivirus and URL‑reputation vendors, none of which reported a detection; this absence of detections does not constitute confirmation of safety. The lack of TLS encryption, combined with the reward‑oriented page title, aligns with typical generic phishing patterns that lure victims into providing credentials or personal data.
Because the infrastructure is hosted behind Cloudflare, attribution of the underlying server is obscured, and the exact payload or credential‑harvesting mechanism remains unknown. Defenders should continue to monitor the IP address 172.66.47.95 for any re‑activation, enforce blocklist rules for the domain, and consider adding the host to internal URL filtering policies. Network traffic to this domain should be logged and examined for potential credential submissions, and any related indicators of compromise should be shared with broader threat‑sharing communities to aid in rapid detection of repeat use.
网络安全情报
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS0 Zero | srv001.cfd |
malicious | Sinkholed |
威胁响应 Pipeline
公共封禁名单状态
VirusTotal 分析
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。