Lompat ke laporan keamanan
Checked 09/08/2026 Ref 8C266DEA

MALICIOUS — CRITICAL

Pemeriksaan phishing dan keamanan billion-3f8.pages.dev

billion-3f8[.]pages[.]dev

Analysis indicates that the domain billion-3f8.pages.dev was created on 2 September 2020 and is hosted on Cloudflare Pages, resolving to the IP address 172.66.46.248.

92/100 evidence score · Critical
VirusTotal
14/91
Blocklists
No stored match
Ketersediaan
Dapat dijangkau · akses dibatasi · HTTP 403
2026-06-12 09:04 UTCDapat dijangkau · akses dibatasi · HTTP 403

Do not enter credentials, seed phrases, payment details, or personal information on this domain.

⚠️
Domain ini telah ditandai sebagai berbahaya
Mesin keamanan melaporkan deteksi: 14. Berhati-hatilah — jangan memasukkan kredensial atau informasi pribadi.
Jump to section
Ringkasan laporan

billion-3f8.pages.dev — Dapat dijangkau · akses dibatasi (HTTP 403). Ringkasan bukti: VirusTotal 14/91 (Criminal IP, alphaMountain.ai, BitDefender, CyRadar, ESET); PhishDestroy score 92/100. Registrar: Cloudflare Pages.

Analisis terperinci PhishDestroy AI di bawah tetap berbahasa Inggris untuk menjaga catatan forensik asli.

Evidence Analysis

Ref 8C266DEA

Analysis indicates that the domain billion-3f8.pages.dev was created on 2 September 2020 and is hosted on Cloudflare Pages, resolving to the IP address 172.66.46.248. The domain appears on a single security blocklist and is specifically listed by PhishDestroy as a malicious site. VirusTotal scans have recorded detections from 14 of 91 security vendors, confirming that the domain is presently flagged by multiple independent engines.

The registration through Cloudflare Pages suggests the use of a reputable CDN provider to hide the true origin of the content, a common tactic in phishing campaigns that rely on rapid deployment and easy teardown. The elevated risk rating and active status indicate that the site is still reachable and may be used to harvest credentials or deliver further malicious payloads. While the available data does not reveal the exact page title, targeted brand, or the specific phishing kit employed, the combination of blocklist inclusion, vendor detections, and the Cloudflare Pages infrastructure provides sufficient evidence to classify the domain as a confirmed phishing resource.

Defenders should add the domain and its resolved IP address to firewall and DNS filtering rules, monitor for any outbound connections to the IP, and consider sharing the indicator set with internal threat‑intel teams. Continuous re‑scanning with VirusTotal or similar services is recommended to track any changes in detection counts. Until further analysis of the hosted content is performed, the domain remains a high‑confidence malicious indicator.

Stored source results

Recorded verdicts and infrastructure observations for this domain.

VirusTotal
VirusTotal
14 det.
URLScan
URLScan
Sertifikat TLS
Google Trust Services
Usia
5.9 yr
Status terpantau
Dapat dijangkau · akses dibatasi 403
PhishDestroy
Daftar Hapus
Terdaftar
Cakupan data12 recorded checks
VirusTotal 14 / 91 URLQuery tidak diperiksa PhishStats tidak diperiksa OTX no community references CF Radar scan completed URLScan capture laporan yang disimpan URLScan verdict Analisis selesai Pemblokiran DNS tidak diperiksa TLS valid certificate, 39d WHOIS 72 mo old Tangkapan layar tangkapan eksternal Rantai pengalihan tidak diselidiki

Alur Tanggapan Ancaman Pipeline

Penemuan
Checks
Reports
Ketersediaan
11/13
Ancaman Telah Diterima
billion-3f8.pages.dev telah terdeteksi dan dimasukkan ke dalam antrian untuk analisis menyeluruh
12/06/2026
URLScan.io Capture
Stored URLScan report with capture artifacts
URLScan Verdict
Analisis URLScan selesai; hasil tangkapan web ini tidak mengubah keputusan ancaman halaman · score 0
01/08/2026
Cloudflare Radar Report
A stored Cloudflare Radar report is available. The report link alone is not a malicious verdict and does not prove that every network field was captured.
VirusTotal
14/91 recorded on VirusTotal
29/07/2026
Google Safe Browsing
29/07/2026
Forensic Evidence Collected
Stored evidence from URLScan.io, stored screenshot
Technical Analysis Recorded
Laporan tersebut berisi teknologi tersimpan atau hasil analisis forensik.
09/08/2026
Content Observed Unavailable
Pemantauan mencatat respons yang tidak tersedia (HTTP 403); penyebabnya belum diketahui secara independen.
29/07/2026
VT detections increased by 3
+3 new detections (15 → 18): Criminal IP, MalwareURL, VIPRE
25/06/2026
Complaint Draft Available
Tidak ada penyerahan yang dicatat. Anda dapat membuat draf, meninjaunya, dan menyerahkannya sendiri ke otoritas yang sesuai.
Daftar yang Dihapus Telah Dipublikasikan
12/06/2026
Monitoring Continues
Domain tetap dapat dijangkau atau aksesnya dibatasi; pemeriksaan di masa depan dapat memperbarui pengamatan ini.

Status Daftar Blokir Publik

Tangkapan tersimpan

Intelijen Domain

Domain
URLScan Verdict Analisis selesai score 0 report ↗
Server / ASN cloudflare · AS13335 Cloudflare, Inc.
IP Context Cloudflare shared edge origin IP hidden Reputasi Edge-IP tidak dikaitkan dengan domain ini.
Penyedia platform Cloudflare Pages
Alamat IP 172.66.46.248 CDN
LokasiCA Toronto, CA
JaringanAS13335 · Cloudflare, Inc.
IP asal tersembunyi di balik proksi CDN. Hasil IP terbalik untuk alamat edge berisi penyewa yang tidak terkait; menemukan asal memerlukan DNS pasif atau data transparansi sertifikat.
Status HTTP403 Forbidden
Elapsed Since First Report 47 days
Yang kami hitung Raw elapsed time since the first stored abuse report. It is not a registrar response-time measurement. Latest observed status: Dapat dijangkau · akses dibatasi.
Isi setiap laporan Catatan laporan keluar yang disimpan dapat merujuk pada bukti yang tersedia pada saat itu, seperti keputusan vendor, data pendaftaran, detail hosting, klasifikasi, atau tangkapan layar. Halaman ini tidak menyimpulkan secara pasti muatan yang dikirimkan, penerimaan, pengakuan, atau tindakan oleh penerima.
Rincian teknisDNS, SAN SSL, cap waktu
Pertama Kali Terdeteksi12/06/2026
IoC Extractionscanned 01/08/20260 wallet · 0 Telegram IoCs
Submitted URLhttp://billion-3f8.pages.dev/privacy-centers
TLS Fingerprint
TLS Observationvalid from 09/06/2026scanned 29/07/2026
Judul Halaman
Suspected Phishing | Cloudflare
Sertifikat TLS
Valid transport encryption · Diterbitkan oleh Google Trust Services · valid for 39 days
Teknologi · 3 identified
HSTS
Keamanan

HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.

www.rfc-editor.org Keyakinan 100%
Cloudflare
CDN

Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.

www.cloudflare.com Keyakinan 100%
HTTP/3
Miscellaneous

HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.

httpwg.org Keyakinan 100%
Detected via Cloudflare Radar · Wappalyzer engine
Laporkan Domain Ini Kirimkan bukti & bantu lindungi orang lain

Analisis VirusTotal

14 / Vendor keamanan 91 menandai domain ini
View on VT
Last analyzed Previous stored snapshot: 15 detections
Criminal IP
alphaMountain.ai
BitDefender
CyRadar
ESET
Forcepoint ThreatSeeker
Fortinet
G-Data
Gridinsoft
Lionic
MalwareURL
Sophos
VIPRE
Webroot
Analisis Performa Situs

Google PageSpeed Insights — mobile performance audit of billion-3f8.pages.dev · checked Jul 29, 2026

100
Good
Performance
FCP
0.77s
First Contentful Paint
LCP
0.77s
Largest Contentful Paint
CLS
0.001
Cumulative Layout Shift
TBT
0ms
Total Blocking Time
SI
0.77s
Speed Index
Powered by Google PageSpeed Insights · Mobile strategy · Scores: 90-100 Good 50-89 Needs Work 0-49 Poor
Bukti & Laporan EksternalIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
If credentials were compromised, report immediately. Do not engage with recovery scammers.

Jika Anda memasukkan kredensial akun, informasi pribadi atau pembayaran, atau mengunduh file dari domain ini, segera ambil tindakan. Di bawah ini adalah sumber daya untuk membantu Anda melaporkan insiden tersebut dan melindungi diri Anda sendiri.

Europol
Temukan saluran pelaporan resmi untuk negara UE Anda
National police directory
Waspadalah terhadap penipu yang mengatasnamakan pemulihan! Penjahat dapat menghubungi korban lagi sambil berpura-pura menjadi penyelidik, pengacara, atau agen pemulihan. Jangan membayar biaya di muka atau membagikan kredensial. Pelajari lebih lanjut tentang penipuan dalam proses pemulihan →

Laporkan kepada Pihak Berwenang di Daerah Anda

Pilih negara Anda untuk mendapatkan kontak resmi kejahatan dunia maya, atau membuat draf pengaduan →.

Direktori 97 negara
Draf yang dibantu AI — detail insiden diproses oleh penyedia AI Tinjau dan kirimkan sendiri
Sematkan Laporan IniRead-only HTML widget
HTML · IFRAME

Sematkan Laporan Ini

Bagikan informasi ancaman ini di situs web atau blog Anda

embed.html
<iframe
  src="https://phishdestroy.io/id/embed/domain/billion-3f8.pages.dev"
  title="PhishDestroy threat report for billion-3f8.pages.dev"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>