# us-en-io-download.pages.dev — SUSPICIOUS > us-en-io-download.pages.dev hosts fake file hosting service. PhishDestroy reports 0 of 95 VirusTotal detections. Check the full report. ## Summary PhishDestroy identifies us-en-io-download.pages.dev as an active domain distributing malicious files under the guise of legitimate file hosting services. This domain is currently under investigation as a generic phishing host, with no specific brand impersonation identified at this time. The threat remains active and is being monitored for further indicators of compromise. This domain was flagged by 0 of 95 VirusTotal vendors as of the latest scan, indicating a low detection rate despite its suspicious functionality. Registered through Cloudflare, Inc., the domain resolves to IP address 172.66.46.248 and operates under a Google Trust Services SSL certificate, which may be leveraged to appear legitimate. The domain’s recent creation and lack of blocklist entries suggest it is a newly deployed threat vector, potentially designed to evade early detection systems. Users and organizations are strongly advised to block traffic to and from us-en-io-download.pages.dev immediately. Given the domain’s low VirusTotal detection rate, traditional security tools may not flag it, increasing the risk of accidental exposure. Enterprises should update firewall rules, DNS sinkholes, and endpoint protection policies to preemptively block this domain. Additionally, employees should be warned against downloading files from untrusted sources, particularly those hosted on unfamiliar or newly registered domains. Further investigation is underway to determine if this domain is part of a larger phishing campaign or operates in conjunction with other malicious infrastructure. ## Threat Details - Verdict: SUSPICIOUS - Site status: unknown (HTTP ?) ## Domain Intelligence - Registrar: Cloudflare, Inc. - IP: 172.66.46.248 ## Detection Status - VirusTotal: 0 vendors flagged - Google Safe Browsing: clean - Blocklists: 0 hits ## Evidence - Cloudflare Radar: https://radar.cloudflare.com/domains/us-en-io-download.pages.dev - PhishDestroy: https://phishdestroy.io/domain/us-en-io-download.pages.dev/ - LLM endpoint: https://phishdestroy.io/domain/us-en-io-download.pages.dev/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/us-en-io-download.pages.dev/ Last updated: 2026-04-05