MALICIOUS — CRITICAL
فحص التصيد والأمان للنطاق networkchains-8wb.pages.dev
networkchains-8wb[.]
PhishDestroy identifies a credential-harvesting campaign hosted at networkchains-8wb.pages.dev that mimics corporate login portals to steal Microsoft 365 credentials.
- VirusTotal
- 3/91
- Blocklists
- No stored match
- التوفر
- آخر نشاط معروف · HTTP 200
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
networkchains-8wb.pages.dev — آخر نشاط معروف (HTTP 200). انتحال العلامة التجارية: Microsoft; نوع الاحتيال: Brand Impersonation. ملخص الأدلة: VirusTotal 3/91 (alphaMountain.ai, Fortinet, Sophos); PhishDestroy score 74/100. مسجّل النطاق: Cloudflare.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
Evidence Analysis
PhishDestroy identifies a credential-harvesting campaign hosted at networkchains-8wb.pages.dev that mimics corporate login portals to steal Microsoft 365 credentials. The page is served over HTTPS via Cloudflare Pages, resolving to IP 188.114.97.3 and has evaded detection by all 95 VirusTotal engines so far. Visitors entering any credentials are immediately transmitted to attacker-controlled infrastructure, risking account takeover and lateral movement in cloud environments.
PhishDestroy’s investigation confirms this domain was registered through Cloudflare, Inc. and shows zero detections on VirusTotal as of the latest scan. The page was built on Cloudflare’s Pages platform and currently points to the Cloudflare IP range 188.114.97.3 with no additional infrastructure enrichment yet visible. Because Cloudflare Pages allows rapid deployment of spoofed login pages, threat actors can iterate campaigns faster than traditional hosting providers, increasing the likelihood of successful credential collection before detection occurs.
If you visited networkchains-8wb.pages.dev and entered any credentials, assume your Microsoft 365 or related corporate account has been compromised. Immediately change your password using a known-clean device, enable multi-factor authentication if not already enabled, and report the incident to your IT security team. Scan recent sign-in logs for anomalous activity and revoke any unrecognized sessions or OAuth tokens. Do not reuse the exposed password on other systems. Forward the URL or any screenshots to your security team for forensic analysis and indicator-of-compromise extraction.
Stored source results
Recorded verdicts and infrastructure observations for this domain.
نطاق تغطية البيانات12 recorded checks
استخبارات أمن الشبكات
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
تحليل VirusTotal
الأدلة المؤرشفة
تحليل أداء الموقع
Google PageSpeed Insights — mobile performance audit of networkchains-8wb.pages.dev · checked Mar 26, 2026
الأدلة والتقارير الخارجيةIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.