Windows User-Agent requests for domain names are hijacked to other websites

No result

At first I found that my domain was hijacked (access jumped to other phishing sites), so I checked if the server was attacked, but there was no trace of any attack. Secondly, I suspected whether Cloudflare access to the source server was hijacked, but it was not the reason. After I opened Under Attack Mode and set the firewall rules (all blocked), but the User-Agent carrying Windows will still automatically 301 jump to the phishing site, not carrying can return the results normally.
Then I set up a firewall and blocked all requests, but the problem still persists, and it didn’t log any requests that contains Windows User-Agent.

When I turned on firewall in Cloudflare:

  1. UA didn’t contain Windows: 1020 error
  2. UA contain Windows (No log in firewall): 301 redirect to harmful URL

  1. At first I thought that Cloudflare was being hijacked when requesting the source server, so I changed the SSL/TLS encryption mode to Full (strict), but the issue still exists

  2. Then I turned on Under Attack Mode, and requests without a Windows User-Agent displayed authentication normally

  3. Then I set my Cloudflare firewall rules to deny all requests, but the issue still exists

Yes, used cert by Let’s Encrypt.

  1. Check my vultr server stats (is it being attacked? No)
  2. Set SSL/TLS encryption mode to Full (strict)
  3. Set Cloudflare Firewall: Deny ALL
  4. Go to Liberate the Hostname
    The issue still exists.

Yes, I tried by curl and Chrome in my macOS computer and Windows Server.

All right, should not be Workers. You said you tried

already, right? Did you run this also on the naked domain?

yes, but still not working

Oh, it should be the cause of this, thank you!

Absolutely, you can go through to verify when that was set up and by whom.

Maybe reset the password and access credentials.


