MALICIOUS — HIGH
Analyse phishing et sécurité de phanttm-en.pages.dev
phanttm-en[.]
Analysis of phanttm-en.pages.dev indicates a credential phishing operation hosted on Cloudflare Pages infrastructure.
- VirusTotal
- 3/95
- Blocklists
- No stored match
- Disponibilité
- Accessible · accès restreint · HTTP 403
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
phanttm-en.pages.dev — Accessible · accès restreint (HTTP 403). Usurpation de l'identité de la marque : Genericcloudflare; Type d'arnaque : Credential Phishing. Résumé des preuves: VirusTotal 3/95 (ChainPatrol, alphaMountain.ai, Fortinet); URLScan malicious verdict; PhishDestroy score 65/100. Bureau d’enregistrement: Cloudflare.
L’analyse détaillée de PhishDestroy AI reste en anglais afin de préserver le relevé forensique original.
Evidence Analysis
Analysis of phanttm-en.pages.dev indicates a credential phishing operation hosted on Cloudflare Pages infrastructure. The domain, registered on February 21, 2026, through Cloudflare, Inc., is currently offline, returning an HTTP 403 status with a page title explicitly labeled 'Suspected phishing site | Cloudflare.' This suggests Cloudflare's automated systems or manual review flagged the content prior to takedown. The domain resolves to IP 188.114.96.3 (AS13335, Cloudflare, Inc., US), a shared hosting environment commonly used for both legitimate and malicious content. SSL certificate issued by Google Trust Services (WE1) confirms encrypted connections, though encryption alone does not indicate legitimacy. Detection data is limited but consistent with phishing activity: three of 95 security vendors on VirusTotal flagged the domain, and it appears on one security blocklist (PhishDestroy).
Gridinsoft assigns a trust score of 0/100, reinforcing the malicious classification. No specific brand impersonation or phishing kit is identified in the available data; the scam type is categorized as credential phishing based on the provided intelligence. Nameservers (ryleigh.ns.cloudflare.com, nicolas.ns.cloudflare.com) and detected technologies (HSTS, Cloudflare, HTTP/3) align with typical Cloudflare-hosted properties, offering no unique attribution beyond the hosting provider. Defenders should treat this domain as confirmed malicious for credential harvesting. Block DNS resolution and HTTP/HTTPS traffic to 188.114.96.3 for this domain.
Monitor Cloudflare Pages for similar patterns (e.g., newly registered subdomains under pages.dev with phishing-related page titles or HTTP 403 responses). While the domain is offline, historical logs should be reviewed for prior connections, particularly from endpoints handling sensitive credentials.
Stored source results
Recorded verdicts and infrastructure observations for this domain.
Couverture des données12 recorded checks
Processus de réponse aux menaces Pipeline
Statut de la liste de blocage publique
Analyse forensique
Technologies · 3 identified
HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org Confiance à 100 %Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com Confiance à 100 %HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org Confiance à 100 %Analyse VirusTotal
Analyse des performances du site
Google PageSpeed Insights — mobile performance audit of phanttm-en.pages.dev · checked Apr 12, 2026
Données factuelles et rapports externesIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.