sp12ct-varnes-biz-prondik-zalmor[.]pages[.]dev
“Meta for Business | Page Appeal”
Analysis of the domain sp12ct-varnes-biz-prondik-zalmor.pages.dev indicates that it is actively being used for a generic phishing campaign. The site is hosted on Cloudflare Pages, a serverless static‑site offering that provides a shared infrastructure and masks the underlying IP address, making attribution difficult. The domain appears on two public blocklists, PhishDestroy and OpenPhish, both of which classify it as a phishing host.
VirusTotal has received submissions for the domain and 15 of 91 scanned security engines returned a malicious verdict, reinforcing the suspicion that the content is malicious. No additional intelligence such as SSL certificate details, HTTP response codes, or page title is available in the current data set, so the exact nature of the landing page cannot be confirmed. The limited visibility is typical for rapidly deployed phishing infrastructure that relies on short‑lived domains created on a CDN platform.
Defenders should block the domain at network perimeter and DNS resolvers, monitor for any outbound connections to the Cloudflare edge network associated with the domain, and consider adding the domain to internal blocklists. Ongoing surveillance of Cloudflare Pages registrations that match similar naming patterns may help identify future iterations. Because the domain is flagged by multiple reputable blocklists and has a non‑trivial detection rate on VirusTotal, the risk rating is elevated and the infrastructure should be treated as hostile until further forensic evidence becomes available.
Threat Response Pipeline
Public Blocklist Status
Domain Intelligence
Technical detailsDNS, SSL SANs, timestamps
Threat Intel Cross-Reference · source references
VirusTotal Analysis
Archived Evidence
Site Performance Analysis
Google PageSpeed Insights — mobile performance audit of sp12ct-varnes-biz-prondik-zalmor.pages.dev · checked Aug 3, 2026
Site Configuration Analysis
Evidence & External Reports
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive