MALICIOUS — CRITICAL
webmaskport[.]pages[.]dev
PhishDestroy identifies the actively malicious domain webmaskport.pages.dev as a credential theft endpoint engaged in generic phishing operations.
- VirusTotal
- 14/94
- Blocklists
- 1 · ScamSniffer
- Disponibilité
- Accessible · accès restreint · HTTP 403
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
webmaskport.pages.dev — Accessible · accès restreint (HTTP 403). Usurpation de l'identité de la marque : Genericcrypto; Type d'arnaque : Credential Phishing. Résumé des preuves: VirusTotal 14/94 (ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, CyRadar); URLScan malicious verdict; 1 external blocklist match (ScamSniffer); PhishDestroy score 97/100. Bureau d’enregistrement: Cloudflare.
L’analyse détaillée de PhishDestroy AI reste en anglais afin de préserver le relevé forensique original.
Evidence Analysis
PhishDestroy identifies the actively malicious domain webmaskport.pages.dev as a credential theft endpoint engaged in generic phishing operations. This domain is currently live and poses an elevated risk to unsuspecting users, with confirmed malicious infrastructure and detection across multiple security platforms. webmaskport.pages.dev was flagged by 13 of 95 VirusTotal vendors, resolving to IP address 172.66.47.92 through Cloudflare, Inc. as registrar. The domain utilizes a Let's Encrypt SSL certificate, indicating a false appearance of legitimacy. While specific creation date and blocklist counts were not disclosed in available intelligence, the domain's detection profile and infrastructure alignment suggest recent deployment targeting credential harvesting operations. Trust scores across security vendors remain critically low, reinforcing its malicious classification. As of the latest assessment, webmaskport.pages.dev remains active and operational. PhishDestroy strongly advises immediate network and endpoint blocking of this domain and its associated IP (172.66.47.92). Users should avoid interaction with any links or content originating from this domain to prevent credential theft or further compromise. Security teams are urged to update firewall rules, DNS sinkholes, and endpoint protection lists. If exposure has occurred, initiate incident response protocols including credential rotation and forensic investigation. Monitor for associated indicators of compromise (IOCs) due to potential lateral movement risks.
Couverture des données12 recorded checks
Renseignements sur la sécurité réseau
Processus de réponse aux menaces Pipeline
Statut de la liste de blocage publique
Analyse forensique
Technologies · 6 identified
Popular CSS framework for responsive, mobile-first web development.
Modern mobile touch slider with hardware-accelerated transitions.
Fast, small JavaScript library simplifying HTML manipulation, event handling, and Ajax.
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Analyse VirusTotal
Analyse des performances du site
Google PageSpeed Insights — mobile performance audit of webmaskport.pages.dev · checked Mar 28, 2026
Données factuelles et rapports externesIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.