wldsf42skrp-zbkpthb-0c3f8d-wlq87c[.]pages[.]dev
“Meta for Business | Page Appeal”
wldsf42skrp-zbkpthb-0c3f8d-wlq87c.pages.dev — Nicht bestätigt. Zusammenfassung der Beweislage: VirusTotal 14/91 (alphaMountain.ai, BitDefender, ESET, Forcepoint ThreatSeeker, Fortinet); PhishDestroy score 98/100. Registrar: Cloudflare Pages.
Die ausführliche Analyse von PhishDestroy AI bleibt auf Englisch, damit der ursprüngliche forensische Bericht unverändert bleibt.
Analysis of wldsf42skrp-zbkpthb-0c3f8d-wlq87c.pages.dev indicates that the domain is actively being used for a generic phishing operation as of the report date, August 04, 2026. The domain is listed on two public security blocklists and is explicitly blocked by the PhishDestroy and OpenPhish feed providers. VirusTotal has recorded detections from 11 of 91 scanned security vendors, confirming that a subset of anti‑malware engines consider the host malicious. The threat is classified with an elevated risk level and remains active in the intelligence feed.
Infrastructure observations show the domain resolves under the pages.dev sub‑domain, a hosting namespace commonly associated with cloud‑based static site services. No additional IP or autonomous system details were supplied in the available intelligence, and SSL/TLS information was not disclosed, limiting further network‑level attribution. The page title and any brand impersonation have not been released, so the precise visual content of the site cannot be confirmed at this time. Defenders should treat the domain as a confirmed phishing source.
Immediate mitigation steps include adding the domain to local and network‑level blocklists, ensuring that any security solutions ingest the PhishDestroy and OpenPhish feeds, and configuring URL filtering to deny traffic to pages.dev sub‑domains that appear on blocklists. Continuous monitoring of VirusTotal and other multi‑engine scanners for changes in detection counts is recommended, as additional vendor detections may surface. Because the underlying hosting provider may host both legitimate and malicious content, broader blocking of the entire pages.dev namespace should be considered only after assessing impact on legitimate services. Incident response teams should also review any logs for recent connections to this domain to identify potential compromise attempts.
Pipeline zur Reaktion auf Sicherheitsbedrohungen
Status der öffentlichen Sperrliste
Gespeicherte Aufnahme
Domain-Intelligenz
Technische DetailsDNS, SSL-SANs, Zeitstempel
VirusTotal-Analyse
Archivierte Beweise
Website-Performanceanalyse
Google PageSpeed Insights — mobile performance audit of wldsf42skrp-zbkpthb-0c3f8d-wlq87c.pages.dev · checked Aug 4, 2026
Analyse der Website-Konfiguration
Nachweise und externe Berichte
Wurden Sie von dieser Website betroffen?
Wenn Sie Kontoanmeldeinformationen, persönliche oder Zahlungsinformationen eingegeben oder eine Datei von dieser Domain heruntergeladen haben, ergreifen Sie sofort Maßnahmen. Nachfolgend finden Sie Ressourcen, die Ihnen helfen, den Vorfall zu melden und sich zu schützen.
Melden Sie sich bei Ihren örtlichen Behörden
Wählen Sie Ihr Land aus, um Offizielle Kontakte im Bereich Cyberkriminalität oder einen Beschwerdeentwurf erstellen → zu erhalten.
Jede beliebige Domain prüfen
Bedrohungsanalyse anhand gespeicherter Blocklisten, WHOIS, DNS und öffentlicher Scan-Beweise
Jetzt scannenPhishing melden
Melden Sie verdächtige Domains an unsere Bedrohungsdatenbank – schützen Sie die Community
MeldenEchtzeit-Bedrohungsfeed
Aktuelle Phishing-Meldungen und beobachtete Verfügbarkeitsänderungen
ÜberwachenBleiben Sie auf dem Laufenden, bleiben Sie sicher
Beobachten Sie aktuelle Bedrohungen oder legen Sie Widerspruch gegen diesen Eintrag ein, wenn Sie der Meinung sind, dass es sich um einen Fehlalarm handelt