# doc-exdus-web.pages.dev — SUSPICIOUS > doc-exdus-web.pages.dev is flagged for low-risk phishing activity. Stay alert and avoid sharing personal info. Check your security with PhishDestroy now. ## Summary PhishDestroy identifies doc-exdus-web.pages.dev as a low-risk generic phishing domain. The site is currently active and classified under phishing due to suspicious characteristics that may lead users to disclose sensitive information. This domain is registered through Cloudflare, Inc., and resolves to IP address 172.66.44.104. VirusTotal analysis shows only 2 of 95 security vendors flagging this domain, indicating a relatively low detection rate. However, the page title being a Cloudflare warning of suspected phishing further supports the caution advised when interacting with this domain. The domain's infrastructure and hosting provider are consistent with common phishing tactics that exploit trusted service platforms. Users are recommended to refrain from entering any personal or financial details on this site. Since the domain remains active and flagged, security tools and users should maintain vigilance. PhishDestroy advises monitoring and blocking access to doc-exdus-web.pages.dev to mitigate potential risk, and encourages users to verify links carefully before interacting. ## Threat Details - Verdict: SUSPICIOUS - Site status: dead (HTTP 403) - Page title: Suspected phishing site | Cloudflare ## Domain Intelligence - Registered: 2026-03-09 13:07:02 - Registrar: Cloudflare, Inc. - Country: US - IP: 172.66.44.104 - IP Country: US - IP City: San Francisco - IP Org: AS13335 Cloudflare, Inc. - Nameservers: kurt.ns.cloudflare.com veda.ns.cloudflare.com - SSL Issuer: Google Trust Services / WE1 ## Detection Status - VirusTotal: 2 vendors flagged Vendors: ["Ermes", "Trustwave"] - Google Safe Browsing: clean - Blocklists: 2 hits Lists: ["PhishDestroy", "MetaMask"] ## Evidence - Screenshot: https://urlscan.io/screenshots/019cd26d-19ea-74b2-9006-d09e4cf7fc2a.png - Cloudflare Radar: https://radar.cloudflare.com/scan/a4c8a080-f582-4c28-959b-dd4126ed6349 - PhishDestroy: https://phishdestroy.io/domain/doc-exdus-web.pages.dev/ - LLM endpoint: https://phishdestroy.io/domain/doc-exdus-web.pages.dev/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/doc-exdus-web.pages.dev/ Last updated: 2026-03-19