sp11ct-ronmel-biz8-kastor-velnix[.]pages[.]dev
“Meta for Business | Page Appeal”
Analysis indicates that the domain sp11ct-ronmel-biz8-kastor-velnix.pages.dev is currently active and has been identified as a generic phishing infrastructure. Registration data shows the domain was provisioned through Cloudflare Pages, a service that provides static site hosting and frequently supplies shared IP space. The domain appears on two independent phishing blocklists, PhishDestroy and OpenPhish, confirming that at least two dedicated anti‑phishing feeds have observed malicious use.
VirusTotal has scanned the domain and 15 of 91 security vendors returned positive detections, reinforcing the suspicion of abusive activity. No additional contextual data such as page title, SSL details, or HTTP response codes are available in the current intelligence set, leaving the exact payload and target brand unverified. The limited visibility suggests the site may be short‑lived or employing techniques to evade deeper fingerprinting.
Defenders should add the domain to network‑level deny lists, enforce DNS filtering against the known blocklists, and monitor for any outbound connections to the hosting IP range associated with Cloudflare Pages. Continuous re‑scanning with VirusTotal and periodic checks of open‑source blocklists are recommended to capture any changes in detection coverage. Because the domain is hosted on a reputable CDN, traditional reputation scores may be misleading; therefore, reliance on the observed blocklist entries and vendor detections is essential for timely mitigation.
Threat Response Pipeline
Public Blocklist Status
Domain Intelligence
Technical detailsDNS, SSL SANs, timestamps
Threat Intel Cross-Reference · source references
VirusTotal Analysis
Archived Evidence
Site Performance Analysis
Google PageSpeed Insights — mobile performance audit of sp11ct-ronmel-biz8-kastor-velnix.pages.dev · checked Aug 3, 2026
Evidence & External Reports
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive