# ecodus-docweb3.pages.dev — SUSPICIOUS > Caution advised for ecodus-docweb3.pages.dev. Site flagged for phishing risk; investigate further before sharing sensitive info. ## Summary PhishDestroy identifies ecodus-docweb3.pages.dev as a domain associated with generic phishing activities. Although currently classified as under investigation, the site exhibits characteristics commonly linked to fraudulent behavior, including a suspicious page title warning users of phishing attempts. The domain is registered through Cloudflare, Inc. and resolves to the IP address 172.66.44.65. Despite no detections on VirusTotal, the domain’s hosting infrastructure and its utilization of Cloudflare services suggest an attempt to obscure malicious intent. The presence on blocklists or threat intelligence feeds has not been confirmed, but the domain’s behavior merits close observation. At this time, the domain remains active with a cautionary status. Users and security practitioners are recommended to avoid interacting with the site or submitting any personal or financial data. Continued monitoring and additional forensic analysis are essential to determine if this domain will be confirmed as a phishing threat or cleared of suspicion in future assessments. ## Threat Details - Verdict: SUSPICIOUS - Site status: dead (HTTP 403) - Page title: Suspected phishing site | Cloudflare ## Domain Intelligence - Registered: 2026-03-10 19:07:02 - Registrar: Cloudflare, Inc. - Country: US - IP: 172.66.44.65 - IP Country: US - IP City: San Francisco - IP Org: AS13335 Cloudflare, Inc. - Nameservers: ignacio.ns.cloudflare.com karsyn.ns.cloudflare.com - SSL Issuer: Google Trust Services / WE1 ## Detection Status - VirusTotal: 4 vendors flagged Vendors: ["ADMINUSLabs", "ChainPatrol", "Fortinet", "Phishing Database"] - Google Safe Browsing: clean - Blocklists: 2 hits Lists: ["PhishDestroy", "MetaMask"] ## Evidence - Screenshot: https://urlscan.io/screenshots/019cd915-1214-73dc-82e4-95df2db3e202.png - Cloudflare Radar: https://radar.cloudflare.com/scan/18f687b8-7508-4bd8-9b95-42470fffdd50 - PhishDestroy: https://phishdestroy.io/domain/ecodus-docweb3.pages.dev/ - LLM endpoint: https://phishdestroy.io/domain/ecodus-docweb3.pages.dev/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/ecodus-docweb3.pages.dev/ Last updated: 2026-03-19