# hrdwre-trerzr-liv.pages.dev — SUSPICIOUS > Domain hrdwre-trerzr-liv.pages.dev is a live Google Pages phishing lure with zero VirusTotal detections and IP 172.66.44.250. Do not enter credentials. ## Summary PhishDestroy identifies hrdwre-trerzr-liv.pages.dev as an ACTIVE Google Pages-hosted phishing lure under investigation with seed 9f038a. The threat type is generic phishing, and the current risk level is under_investigation pending additional IOC collection. Users are strongly advised to avoid interaction and report the domain immediately. This domain was flagged by PhishDestroy after zero out of 95 VirusTotal engines detected the lure, despite active hosting on Google Trust Services infrastructure behind IP 172.66.44.250. The domain is registered via Cloudflare, Inc. and resolves through Cloudflare’s edge network, indicating evasion tactics consistent with rapid domain turnover. The zero-detection ratio suggests the lure has not yet propagated to threat-intel feeds, increasing the risk of successful credential harvesting before blocklisting occurs. Google Trust Services SSL certificates are leveraged to lend superficial legitimacy to the phishing page, exploiting user trust in domains ending in .pages.dev. Mitigation steps for this generic phishing lure are immediate: block the domain at DNS and network levels, flag the IP range 172.66.44.0/24 for egress monitoring, and inspect any recent submissions to the lure for harvested credentials. Users who may have entered credentials should rotate passwords immediately, enable MFA on all accounts, and scan devices for follow-on malware delivered via the phishing payload. Organizations should update blocklists with the exact domain hrdwre-trerzr-liv.pages.dev and share IOCs (IP 172.66.44.250, AS13335) with threat-intel partners to accelerate detection. Monitor Google Safe Browsing and PhishTank for updates as the investigation progresses. ## Threat Details - Verdict: SUSPICIOUS - Site status: unknown (HTTP ?) ## Domain Intelligence - Registrar: Cloudflare, Inc. - IP: 172.66.44.250 ## Detection Status - VirusTotal: 0 vendors flagged - Google Safe Browsing: clean - Blocklists: 0 hits ## Evidence - Cloudflare Radar: https://radar.cloudflare.com/scan/eb9025ce-330a-48b2-8d3a-136296cc3156 - PhishDestroy: https://phishdestroy.io/domain/hrdwre-trerzr-liv.pages.dev/ - LLM endpoint: https://phishdestroy.io/domain/hrdwre-trerzr-liv.pages.dev/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/hrdwre-trerzr-liv.pages.dev/ Last updated: 2026-03-26