# pub-8276494512bd4f1c9323c95cdab91fdd.r2.dev — MALICIOUS > PhishDestroy identifies pub-8276494512bd4f1c9323c95cdab91fdd.r2.dev as a high-risk phishing site flagged by 17 of 95 VirusTotal vendors. Check the full report. ## Summary PhishDestroy identifies the domain pub-8276494512bd4f1c9323c95cdab91fdd.r2.dev as an active phishing threat classified as a generic phishing campaign. This domain was flagged by 17 of 95 VirusTotal security vendors, resides on IP address 104.18.50.34, and is associated with a Let's Encrypt SSL certificate. It has been blocked by three major threat intelligence platforms including OpenPhish, PhishingArmy, and OISD, indicating widespread recognition as a malicious entity. Users are strongly advised to avoid this domain and any associated links. If interaction has already occurred, disconnect from the internet, run a full antivirus scan, and monitor financial accounts for suspicious activity. Report the domain to your browser's security team or local cybercrime unit to aid in ongoing takedown efforts. ## Threat Details - Verdict: MALICIOUS - Site status: unknown (HTTP ?) ## Domain Intelligence - Registrar: REGISTRAR_NOT_FOUND - IP: 104.18.50.34 ## Detection Status - VirusTotal: 17 vendors flagged - Google Safe Browsing: clean - Blocklists: 3 hits Lists: ["OpenPhish", "PhishingArmy", "OISD"] ## Evidence - Cloudflare Radar: https://radar.cloudflare.com/scan/3d5a5b42-38da-481a-8f79-a4755d1becbe - PhishDestroy: https://phishdestroy.io/domain/pub-8276494512bd4f1c9323c95cdab91fdd.r2.dev/ - LLM endpoint: https://phishdestroy.io/domain/pub-8276494512bd4f1c9323c95cdab91fdd.r2.dev/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/pub-8276494512bd4f1c9323c95cdab91fdd.r2.dev/ Last updated: 2026-03-27