sp12ct-zormel-biz-havdok-prasik[.]pages[.]dev
“Meta for Business | Page Appeal”
This domain sp12ct-zormel-biz-havdok-prasik.pages.dev is currently flagged as a generic phishing site. Infrastructure analysis shows the hostname resolves to IP address 172.66.47.110, which belongs to the Cloudflare Pages hosting platform. Registration metadata indicate the site was provisioned through Cloudflare Pages, a legitimate content‑delivery service that can be abused to host malicious pages. The domain appears on a single security blocklist and has been explicitly blocked by the PhishDestroy feed, providing independent confirmation of malicious intent.
No additional public intelligence such as Safe Browsing entries, OTX reports, or SSL certificate anomalies has been disclosed for this hostname. The page title, brand targeting, and detailed payload have not been published, leaving the content of the site unverified beyond the blocklist indication. Consequently, while the underlying hosting is shared and benign, the specific usage pattern aligns with the phishing classification supplied in the threat feed.
Defenders should immediately add sp12ct-zormel-biz-havdok-prasik.pages.dev to web‑filter allow‑lists for blocking, enforce URL‑based deny rules on perimeter firewalls, and consider broader Cloudflare Pages sub‑domains as high‑risk until further context is gathered. Ongoing monitoring of the IP 172.66.47.110 for new hostnames and periodic re‑query of threat intel sources is advised to capture any evolution of the campaign. Until content analysis becomes available, the safest posture is to treat the domain as malicious and prevent user access.
Threat Response Pipeline
Public Blocklist Status
Stored Capture
Domain Intelligence
Technical detailsDNS, SSL SANs, timestamps
VirusTotal Analysis
Archived Evidence
Site Performance Analysis
Google PageSpeed Insights — mobile performance audit of sp12ct-zormel-biz-havdok-prasik.pages.dev · checked Aug 7, 2026
Site Configuration Analysis
Evidence & External Reports
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive