shepsky-ai[.]pages[.]dev
Evidence Summary
shepsky-ai.pages.dev is currently listed as an active generic phishing infrastructure with an elevated risk rating. The domain was provisioned through Cloudflare Pages, a serverless hosting platform that provides automatic TLS termination and global CDN distribution. Its registration details are limited to the hosting provider, and no separate registrar information is exposed. The domain appears on three independent security blocklists and is explicitly blocked by the PhishDestroy, MetaMask, and SEAL filtering services, indicating that multiple threat‑intel feeds have identified malicious activity associated with it.
VirusTotal analysis shows that two out of ninety‑one scanned security vendors flagged the domain, reinforcing the suspicion that the site is being used for illicit purposes. No public evidence has been released regarding the underlying IP address, autonomous system number, country of operation, or SSL certificate fingerprint, and the HTTP response status has not been documented in the available sources. Consequently, the precise technical footprint of the hosting environment remains uncertain beyond the Cloudflare Pages association.
Defenders are advised to add shepsky-ai.pages.dev to local deny lists, monitor outbound connections for attempts to resolve the domain, and enforce web‑gateway policies that block traffic to any URL resolved to the domain. Continuous threat‑intel feeds should be consulted for any future updates, such as additional vendor detections, changes in blocklist status, or the emergence of a page title that could reveal the targeted brand. Until more granular indicators are disclosed, the recommendation is to treat the domain as hostile and prevent user access.
Data Coverage
Threat Response Pipeline
Blocklist coverage
10 monitored external feeds · stored snapshot Aug 11, 2026
7 monitored external feeds No match
Detection timeline
-
Domain status
Reachable → Unreachable
Domain Intelligence
Technical detailsDNS, TLS names and timestamps
Technologies
5 high-confidence technologies identified
VirusTotal Analysis
Archived Evidence
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive