sp12ct-varnik-biz-keldor-fresmik[.]pages[.]dev
“Meta for Business | Page Appeal”
Analysis of sp12ct-varnik-biz-keldor-fresmik.pages.dev indicates confirmed phishing activity with elevated risk as of August 3, 2026. The domain is hosted on Cloudflare Pages infrastructure, a common vector for rapidly deployed credential-harvesting sites. VirusTotal scanning reveals 15 of 91 security vendors flagging the domain, a detection rate consistent with known phishing pages rather than benign false positives. The domain appears on two security blocklists, including PhishDestroy and OpenPhish, both of which specialize in real-time phishing detection.
No specific brand impersonation or scam subtype is currently confirmed in the available data; the content of the page remains unanalyzed beyond its classification as generic phishing. The domain's structure—using hyphenated, seemingly randomized subdomains—aligns with patterns observed in automated phishing kits designed to evade basic keyword filtering. Cloudflare's registrar role suggests the domain was registered recently or automatically, though exact registration details are not provided in the intelligence. Defenders should treat this domain as active and malicious.
Blocking at the DNS or proxy level is recommended, particularly for organizations with users susceptible to credential theft. Network logs should be reviewed for connections to this domain, and any credentials entered on the site should be considered compromised. Further analysis of the page's HTML or JavaScript may reveal additional indicators, such as redirect chains or embedded malicious scripts, but such examination is not yet documented in the available evidence.
Threat Response Pipeline
Public Blocklist Status
Stored Capture
Domain Intelligence
Technical detailsDNS, SSL SANs, timestamps
Threat Intel Cross-Reference · source references
VirusTotal Analysis
Archived Evidence
Site Performance Analysis
Google PageSpeed Insights — mobile performance audit of sp12ct-varnik-biz-keldor-fresmik.pages.dev · checked Aug 3, 2026
Site Configuration Analysis
Evidence & External Reports
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive