simple-security-page--pinewl[.]replit[.]app
“Sign in to your account”
Evidence Summary
Analysis of simple-security-page--pinewl.replit.app indicates a high-risk phishing domain actively serving social-engineering content as of August 07, 2026. The domain is hosted on Replit infrastructure and resolves to IP address 34.117.33.233, which has been associated with prior malicious activity. Thirteen of ninety-one security vendors on VirusTotal have flagged this domain, and it appears on one security blocklist, suggesting detection by multiple independent engines. Google Safe Browsing explicitly classifies the site as engaging in social engineering, a designation typically reserved for pages designed to deceive users into divulging credentials or sensitive information.
Infrastructure analysis reveals the domain is registered through Replit, a platform commonly used for both legitimate development and transient phishing campaigns due to its ease of deployment and ephemeral hosting capabilities. The IP address 34.117.33.233 is part of Google Cloud infrastructure, which is frequently leveraged by threat actors for its scalability and perceived legitimacy. While the specific content of the page has not been fully analysed, the combination of detection by security vendors, blocklist inclusion, and Safe Browsing classification provides concrete evidence of malicious intent. Defenders should treat this domain as an active threat.
Network-level blocking is recommended, particularly for organisations targeted by credential phishing. The domain’s association with Replit suggests it may be short-lived, but its current detection status and hosting on a cloud provider warrant immediate mitigation. No brand or scam type has been confirmed from available data, so the exact nature of the phishing lure remains uncertain. Further investigation into the page’s content and any associated email or SMS campaigns is advised to determine the scope of the threat.
Data Coverage
Network Security Intelligence
Threat Response Pipeline
Blocklist coverage
10 monitored external feeds · stored snapshot Aug 12, 2026
10 monitored external feeds No match
Detection timeline
-
First recorded
First stored value: Reachable
-
Google Safe Browsing
0 → 1
Stored Capture
Domain Intelligence
Technical detailsDNS, TLS names and timestamps
ICANN OVERSIGHT
Registration: replit.app
Accreditation and RAA context
Accreditation and RAA context
Registrar accreditation and DNS abuse obligations
For the registrable domain replit.app behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Technologies
12 high-confidence technologies identified
VirusTotal Analysis
Archived Evidence
Site Performance Analysis
Google PageSpeed Insights — mobile performance audit of simple-security-page--pinewl.replit.app · checked Aug 7, 2026
Site Configuration Analysis
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive