# play-sopho.pages.dev — SUSPICIOUS > The domain play-sopho.pages.dev is under investigation for potential phishing activity. Exercise caution and avoid sharing sensitive information. ## Summary PhishDestroy identifies play-sopho.pages.dev as a suspicious domain potentially engaged in generic phishing activities. While the exact intent remains under investigation, phishing threats aim to deceive users into divulging personal or financial information, posing risks such as identity theft and financial loss. Vigilance around unfamiliar domains like this is crucial to maintaining online security. This domain is registered through Cloudflare, Inc. and resolves to IP address 172.66.47.93. Despite a clean VirusTotal scan with zero detections among 95 security vendors, the domain's recent registration and hosting on a reputable CDN platform suggest it may be leveraging legitimate infrastructure to evade detection. The absence of current vendor flags does not eliminate risk, emphasizing the need for ongoing monitoring as part of a layered defense strategy. Users are advised to exercise caution when encountering play-sopho.pages.dev or any unsolicited communications referencing it. Avoid clicking on links or providing credentials without verifying the source. Maintaining updated security software, employing multi-factor authentication, and reporting suspicious activity can help mitigate potential harm. PhishDestroy will continue to monitor this domain and provide updates should new intelligence arise. ## Threat Details - Verdict: SUSPICIOUS - Site status: dead (HTTP 403) - Page title: Sophon ## Domain Intelligence - Registered: 2026-03-10 13:07:01 - Registrar: Cloudflare, Inc. - Country: US - IP: 172.66.47.93 - IP Country: US - IP City: San Francisco - IP Org: AS13335 Cloudflare, Inc. - Nameservers: jack.ns.cloudflare.com lina.ns.cloudflare.com - SSL Issuer: Google Trust Services / WE1 ## Detection Status - VirusTotal: 3 vendors flagged Vendors: ["ChainPatrol", "Fortinet", "Gridinsoft"] - Google Safe Browsing: clean - Blocklists: 3 hits Lists: ["PhishDestroy", "MetaMask", "ScamSniffer"] ## Evidence - Screenshot: https://urlscan.io/screenshots/019cd79f-9789-735e-b95b-2264002b9263.png - Cloudflare Radar: https://radar.cloudflare.com/scan/0013da62-8e47-4acf-9599-e66aa072bc69 - PhishDestroy: https://phishdestroy.io/domain/play-sopho.pages.dev/ - LLM endpoint: https://phishdestroy.io/domain/play-sopho.pages.dev/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/play-sopho.pages.dev/ Last updated: 2026-03-19