sp12ct-vomsar-biz-zelnik-prandel[.]pages[.]dev
“Meta for Business | Page Appeal”
sp12ct-vomsar-biz-zelnik-prandel.pages.dev is currently listed as an active generic phishing infrastructure. The domain is hosted on Cloudflare Pages, indicating the use of a serverless web‑hosting platform that masks the underlying IP address behind Cloudflare’s network. VirusTotal has recorded detections from 14 of 91 scanning engines, demonstrating that multiple security products have identified the site as malicious. Independent phishing‑specific blocklists have also taken action: PhishDestroy and OpenPhish both include the domain, and it appears on two additional security blocklists.
These listings corroborate the classification and suggest that the domain is being actively used to distribute fraudulent content. No public SSL certificate details, HTTP status codes, or page‑title information have been disclosed, limiting the depth of technical fingerprinting. Consequently, while the presence on reputable blocklists and the multi‑vendor VirusTotal detections provide strong evidence of malicious intent, the exact payload, targeted brand, or victim interaction flow remain unknown.
Defenders should block the domain at perimeter firewalls, DNS resolvers, and proxy filters, and update any threat‑intel feeds with the observed indicators. Continuous monitoring of Cloudflare Pages registrations for similar sub‑domain patterns is recommended, as the platform can be leveraged to spin up short‑lived phishing sites. Organizations should also consider sharing any future observations, such as HTTP response headers or page titles, with community blocklist operators to improve collective detection.
Threat Response Pipeline
Public Blocklist Status
Domain Intelligence
Technical detailsDNS, SSL SANs, timestamps
Threat Intel Cross-Reference · source references
VirusTotal Analysis
Archived Evidence
Site Performance Analysis
Google PageSpeed Insights — mobile performance audit of sp12ct-vomsar-biz-zelnik-prandel.pages.dev · checked Aug 3, 2026
Evidence & External Reports
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive