MALICIOUS — CRITICAL
twitter-preview[.]pages[.]dev
2 of 91 security engines flagged the domain; the latest stored check returned HTTP 200.
- VirusTotal
- 2/91
- Blocklists
- No stored match
- Disponibilité
- Dernier actif connu · HTTP 200
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
twitter-preview.pages.dev — Dernier actif connu (HTTP 200). Usurpation de l'identité de la marque : Blast; Type d'arnaque : Brand Impersonation. Résumé des preuves: VirusTotal 2/91 (alphaMountain.ai, Webroot); PhishDestroy score 76/100. Bureau d’enregistrement: Cloudflare Pages.
L’analyse détaillée de PhishDestroy AI reste en anglais afin de préserver le relevé forensique original.
Evidence Digest
twitter-preview.pages.dev is classified critical with an evidence score of 76/100. 2 of 91 security engines flagged the domain. Registered 30 Apr 2026 via Cloudflare Pages, hosted on 172.66.47.83 (Cloudflare, Inc., CA). The latest stored check on 9 Aug 2026 returned HTTP 200.
Stored generated summary (templated)cerebras · 13/07/2026
Retained for the record. This text repeats stored detection facts and is not presented as authored analysis.
The domain twitter-preview.pages.dev was registered on April 30 2026 and is currently hosting a page titled “BlastUP Presale – First Launchpad on the Blast”. The page title directly references the Blast brand, matching the classified scam type of brand impersonation. DNS resolution points to IP 172.66.47.83, which belongs to Cloudflare, Inc. and is geolocated to Canada. The site presents a valid TLS certificate issued by Google Trust Services under the WE1 root, indicating standard HTTPS provisioning through Cloudflare Pages. VirusTotal reports that the domain has been scanned by 91 security vendors without a detection, but the absence of flags does not constitute a safety guarantee. The domain is listed on a single public blocklist, PhishDestroy, and receives a Gridinsoft trust score of 0 out of 100, reflecting a high‑risk assessment. As of the report date the site returns HTTP 200, confirming it is actively serving content. No additional technical artefacts such as malicious scripts, redirects, or credential‑harvesting forms have been disclosed. The primary uncertainty lies in the exact content and functionality of the hosted page, which has not been analysed in depth. Defenders should block traffic to the domain, monitor DNS queries for the associated IP, and consider adding the domain to internal blocklists. Continued observation is advised to detect any evolution of the infrastructure or emergence of new indicators.
Couverture des données12 recorded checks
Processus de réponse aux menaces Pipeline
Statut de la liste de blocage publique
Informations sur les domaines
Détails techniquesDNS, SAN SSL, horodatages
Analyse VirusTotal
Données factuelles et rapports externesIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.