# live-download-us.pages.dev — SUSPICIOUS > PhishDestroy identifies live-download-us.pages.dev as a generic cryptolocker phishing site hosting malicious payloads. Resolves to Cloudflare IP 172.66.47.80. ## Summary PhishDestroy identifies live-download-us.pages.dev as an active cryptolocker phishing domain under investigation for distributing malicious payloads posing as software downloads. The threat involves tricking users into downloading encrypted ransomware disguised as legitimate files. This domain’s nature of activity indicates a high-risk attempt to compromise user systems through fake download pages. This domain was flagged by PhishDestroy’s threat intelligence with a risk level marked under investigation. It resolves to Cloudflare IP 172.66.47.80 and is registered through Cloudflare, Inc., using an SSL certificate issued by Google Trust Services. VirusTotal currently shows 0/95 detections, and no entries were found on public blocklists at the time of assessment. The domain’s configuration and use of a Cloudflare IP and Google Trust Services certificate may be leveraged to evade detection by mimicking legitimate infrastructure. To mitigate exposure to this cryptolocker phishing threat, users should avoid interacting with any download prompts or links from this domain. Verify the legitimacy of download sources independently, especially for software or updates. Ensure systems have up-to-date antivirus software and avoid enabling macros or running untrusted files. If interaction occurred, scan the system immediately with reputable security tools and consider revoking permissions if cloud-based services were accessed via this domain. ## Threat Details - Verdict: SUSPICIOUS - Site status: unknown (HTTP ?) ## Domain Intelligence - Registrar: Cloudflare, Inc. - IP: 172.66.47.80 ## Detection Status - VirusTotal: 0 vendors flagged - Google Safe Browsing: clean - Blocklists: 0 hits ## Evidence - Cloudflare Radar: https://radar.cloudflare.com/domains/live-download-us.pages.dev - PhishDestroy: https://phishdestroy.io/domain/live-download-us.pages.dev/ - LLM endpoint: https://phishdestroy.io/domain/live-download-us.pages.dev/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/live-download-us.pages.dev/ Last updated: 2026-04-04