upheld-login-usa[.]pages[.]dev
“Suspected phishing site | Cloudflare”
upheld-login-usa.pages.dev — 内容不可用. 品牌冒充:Genericcloudflare; 诈骗类型:Credential Phishing. 证据摘要: VirusTotal 16/95 (ADMINUSLabs, Criminal IP, alphaMountain.ai, BitDefender, CyRadar); URLScan malicious verdict; CF Radar malicious; PhishDestroy score 95/100. 注册商: Cloudflare.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
Analysis of the domain upheld-login-usa.pages.dev shows that it was registered on February 21 2026 through Cloudflare, Inc. and immediately placed behind Cloudflare’s DNS service (aldo.ns.cloudflare.com, tori.ns.cloudflare.com). The domain resolves to IP 188.114.97.3, which belongs to AS13335 Cloudflare, Inc. located in the United States. HTTPS is served by a Google Trust Services certificate issued to “WE1”, and the server presents HSTS and HTTP/3, indicating a modern Cloudflare edge configuration. An HTTP request returns a 403 status and the page title “Suspected phishing site | Cloudflare”, confirming that the site has been flagged by Cloudflare’s own anti‑phishing mechanisms.
VirusTotal records indicate that 16 of 95 scanned security vendors flagged the domain as malicious, and the domain appears on one public blocklist. Independent monitoring by PhishDestroy also lists the domain as blocked. The Gridinsoft trust score of 0 / 100 further corroborates its malicious reputation. The listed scam type is credential phishing, although the specific targeted brand or login portal has not been disclosed in the available data.
As of the report date (July 23 2026) the site is reported offline, which limits active probing but does not mitigate the risk posed by the infrastructure that may be reused for future campaigns. Defenders should continue to block the domain at perimeter and DNS filters, monitor the associated IP address 188.114.97.3 for any re‑hosting activity, and enforce strict outbound traffic controls to prevent credential exfiltration. Because the domain leverages a reputable CDN, additional scrutiny of Cloudflare‑hosted sub‑domains is advised when similar naming patterns appear. Ongoing collection of any new page content or redirects is recommended to refine attribution and to update detection signatures.
网络安全情报
威胁响应 Pipeline
公共封禁名单状态
取证情报
所用技术 · 3 identified
HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 置信度 100%Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 置信度 100%HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 置信度 100%VirusTotal 分析
网站性能分析
Google PageSpeed Insights — mobile performance audit of upheld-login-usa.pages.dev · checked Mar 2, 2026
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。