⚠️
Suspicious Domain — Listed on PhishDestroy
This domain is on the PhishDestroy threat list. VirusTotal checked 91 security vendors. Analysis is ongoing — exercise caution and do not enter credentials or personal information. Create a complaint draft, review it, and submit it yourself if appropriate.
Domain security & threat intelligence

why-node[.]pages[.]dev

Pemeriksaan phishing dan keamanan why-node.pages.dev

“EVM_RESOLVE”

Threat verdict Critical 76/100 evidence score
Availability Last known active Latest stored reachability observation
Risk signals
Scam type: Generic Phishing Last known active
Jun 15, 2026 Generic Phishing CA CA + more
Ringkasan laporan

why-node.pages.dev: pemeriksaan VirusTotal tersimpan menunjukkan 0 deteksi dari 91 pemindai. Tinjau DNS, SSL, registrar, dan daftar blokir.

Analisis terperinci PhishDestroy AI di bawah tetap berbahasa Inggris untuk menjaga catatan forensik asli.

Evidence Summary
CRITICAL
Ref
29802EC1
Score
76/100
Mode
Evidence v1

PhishDestroy first recorded why-node.pages.dev on Jun 15, 2026. This English evidence brief is rebuilt from the current structured observations stored for the report. The current evidence score, computed from those stored observations, is 76/100.

The latest stored availability state is “Last known active” (HTTP 200) on Aug 2, 2026 at 00:21 UTC. This is a reachability snapshot, not proof of the cause of any outage, restriction, or status change.

VirusTotal returned 0 detections from 91 scanners in the stored check on Jul 27, 2026 at 04:50 UTC. A zero-vendor result is not a safety verdict. The independent blocklist snapshot recorded 0 matches across 10 configured external sources on Aug 2, 2026 at 00:20 UTC. PhishDestroy's own listing is excluded from that count. A zero-match snapshot is not a safety verdict.

Other stored evidence. Google Safe Browsing stored no positive flag on Mar 28, 2026 at 08:00 UTC. This time-bound result is not evidence of safety. AlienVault OTX stored 0 pulse references on Mar 30, 2026 at 09:06 UTC. OTX pulses are community-intelligence references, not vendor verdicts. The Spamhaus DBL snapshot stored no positive result on Jul 14, 2026 at 00:34 UTC. That result is not evidence of safety.

Stored context lists registrar Cloudflare Pages, IP address 172.66.44.136, registration date Mar 27, 2026. Except for the registration date, these fields do not share a source timestamp in this report and may change.

Treat these as stored, time-bound observations rather than a live safety guarantee. Source verdicts and reachability can change, and zero or missing vendor matches never prove that a domain is safe. Avoid interacting with the domain while uncertainty remains, and use the appeal process if this report is inaccurate.

VirusTotal
VirusTotal
0 det.
Gridinsoft
0/100
TLS certificate
Expired or unverified -38d
Usia
4 mo
Observed status
Last known active 200
PhishDestroy
Daftar Hapus
Listed
Cakupan data VirusTotal no detections URLQuery checked — no match OTX no pulses CF Radar no data URLScan capture not submitted URLScan verdict verdict unavailable Pemblokiran DNS not checked TLS expired or unverified WHOIS 4 mo old Screenshot external capture Rantai pengalihan not probed Gridinsoft 0/100

Alur Tanggapan Ancaman Pipeline

Discovery
Checks
Reports
Availability
6/8
Penemuan dan Pengambilan Data Secara Proaktif
Ancaman Telah Diterima
1/1 ✓
Ancaman Telah Diterima
why-node.pages.dev telah terdeteksi dan dimasukkan ke dalam antrian untuk analisis menyeluruh
Jun 15, 2026
Threat Intelligence Checks
VirusTotal · Google Safe Browsing · Forensic Evidence Collected · Technical Analysis Recorded
4/4 ✓
VirusTotal
91 vendors checked on VirusTotal — no vendor detections recorded at check time
Jul 27, 2026
Google Safe Browsing
Mar 28, 2026
Forensic Evidence Collected
Stored evidence from stored screenshot
Technical Analysis Recorded
The report contains stored technology or forensic-analysis results
Aug 02, 2026
Notification Records
Complaint Draft Available
PENDING
Complaint Draft Available
No submission is recorded. You can create a draft, review it, and submit it yourself to the appropriate authority.
Publikasi dan Ketersediaan
DestroyList Published · Monitoring Continues
1/2
Daftar yang Dihapus Telah Dipublikasikan
Jun 15, 2026
Monitoring Continues
The domain remains reachable or access-restricted; future checks may update this observation

Status Daftar Blokir Publik

Pengumpulan Bukti

Stored Capture
2026-06-15 00:27 UTC
Malicious
Forensic screenshot of why-node.pages.dev showing the phishing page layout
IP: 172.66.44.136
Cloudflare Pages
127d old

Intelijen Domain

Domainwhy-node.pages.dev
Server / ASN cloudflare · AS13335 Cloudflare, Inc.
IP Reputation abuse score 0/100 2 reports checked Jul 14, 2026
IP Address 172.66.44.136 CA
GeoCA Toronto, CA
NetworkAS13335 · Cloudflare, Inc.
RegistrationDibuat Mar 27, 2026 (127d)
Status HTTP200
Rincian teknisDNS, SAN SSL, cap waktu
Pertama Kali TerdeteksiJun 15, 2026
TLS Fingerprintc89468169e2f9d76e85971f1ff7ce02f594d1292…
Favicon Hashfavicon96622a8a875c31ba1423307e85cddd29
Page Title
EVM_RESOLVE
TLS Certificate
Expired or unverified · Issued by Google Trust Services / WE1
Laporkan Domain Ini Kirimkan bukti & bantu lindungi orang lain
Analisis Performa Situs

Google PageSpeed Insights — mobile performance audit of why-node.pages.dev · checked Apr 5, 2026

100
Good
Performance
FCP
1.08s
First Contentful Paint
LCP
1.08s
Largest Contentful Paint
CLS
0
Cumulative Layout Shift
TBT
0ms
Total Blocking Time
SI
1.08s
Speed Index
Powered by Google PageSpeed Insights · Mobile strategy · Scores: 90-100 Good 50-89 Needs Work 0-49 Poor

Bukti & Laporan Eksternal

Apakah Anda Terpengaruh oleh Situs Ini?

Kamu tidak sendirian dan tidak ada yang perlu kamu malu-malui. Penipu adalah para penjahat yang cerdik dan memanfaatkan kepercayaan orang lain. Melaporkan pengalaman Anda adalah senjata paling ampuh untuk melawan penipuan — laporan Anda dapat mencegah orang lain menjadi korban dan membantu aparat penegak hukum mengambil tindakan. Diam adalah keunggulan terbesar para penipu. Hancurkan saja.

If you entered account credentials, personal or payment information, or downloaded a file from this domain, take immediate action. Below are resources to help you report the incident and protect yourself.

Waspadalah terhadap penipu yang mengatasnamakan pemulihan! Criminals may contact victims again while pretending to be investigators, lawyers, or recovery agents. Do not pay upfront fees or share credentials. Pelajari lebih lanjut tentang penipuan dalam proses pemulihan →

Laporkan kepada Pihak Berwenang di Daerah Anda

Pilih negara Anda untuk mendapatkan kontak resmi terkait kejahatan siber, or create a complaint draft →

Pilih negara Anda...
Lebih dari 180 negara
Zero-PII — data Anda tidak pernah meninggalkan browser Review and submit it yourself

About This Report: why-node.pages.dev

This report presents the latest stored evidence available to PhishDestroy. Source timestamps are shown where available; availability and vendor verdicts can change after collection.

The site displays a page titled “EVM_RESOLVE”.

why-node.pages.dev has been listed on PhishDestroy as a suspicious domain. Scanned by 91 security vendors — automated detections may take time to update. PhishDestroy threat analysts continue to monitor this domain.

Jika Anda merasa informasi dalam daftar ini tidak akurat, Anda dapat mengajukan banding. Untuk informasi lebih lanjut mengenai metodologi kami, kunjungi situs kami Halaman Pertanyaan yang Sering Diajukan.

Periksa Domain Apa Pun

Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence

Pindai Sekarang

Laporkan Phishing

Laporkan domain yang mencurigakan ke basis data ancaman kami — lindungi komunitas

Report

Pemberitahuan Ancaman Real-Time

Recent phishing reports and observed availability changes

Monitor

Tetap Terinformasi, Tetap Aman

Pantau ancaman secara langsung atau ajukan keberatan terhadap daftar ini jika Anda yakin ini merupakan false positive

Pemberitahuan Ancaman Real-Time Ajukan Banding Terhadap Iklan Ini
HTML · IFRAME

Sematkan Laporan Ini

Bagikan informasi ancaman ini di situs web atau blog Anda

embed.html
<iframe
  src="https://phishdestroy.io/id/embed/domain/why-node.pages.dev"
  title="PhishDestroy threat report for why-node.pages.dev"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>