MALICIOUS — CRITICAL
Verifica phishing e sicurezza per deltaf254-lab.pages.dev
deltaf254-lab[.]
Analysis indicates that the domain deltaf254-lab.pages.dev is actively engaged in cryptocurrency-themed phishing as of July 19, 2026.
- VirusTotal
- 3/91
- Blocklists
- 3 · MetaMask, ScamSniffer
- Disponibilità
- Ultimo attivo conosciuto · HTTP 200
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
deltaf254-lab.pages.dev — Ultimo attivo conosciuto (HTTP 200). Riepilogo delle prove: VirusTotal 3/91 (alphaMountain.ai, Forcepoint ThreatSeeker, Gridinsoft); 3 external blocklist matches (MetaMask, ScamSniffer, SEAL); PhishDestroy score 84/100. Registrar: Cloudflare Pages.
L’analisi dettagliata di PhishDestroy AI resta in inglese per preservare il rapporto forense originale.
Evidence Analysis
Analysis indicates that the domain deltaf254-lab.pages.dev is actively engaged in cryptocurrency-themed phishing as of July 19, 2026. The domain resolves to IP address 172.66.44.147, which is hosted on Cloudflare infrastructure in Canada. The page title, 'AMERICA IS BACK | $AIB,' suggests a focus on a cryptocurrency asset or token, though the specific brand or project being impersonated is not confirmed in available data. The domain is registered through Cloudflare Pages and uses a Let's Encrypt SSL certificate (identifier YE2), which is consistent with both legitimate and malicious sites leveraging free certificate authorities. The domain appears on three security blocklists and is actively blocked by PhishDestroy, MetaMask, and SEAL, indicating detection by multiple independent threat intelligence sources. Two of 91 security vendors on VirusTotal flag the domain as malicious, though the absence of broader detection does not preclude its classification as a threat. The HTTP status code 200 confirms the site is currently accessible. Infrastructure analysis reveals no anomalous registration patterns, but the use of Cloudflare Pages aligns with common phishing tactics to evade takedowns and obscure hosting origins. Defenders should treat this domain as high-risk and prioritize blocking it at the network and endpoint levels. Given its association with cryptocurrency-themed phishing, wallet providers and exchanges are advised to monitor for references to this domain in transaction metadata or user reports. Further investigation into the $AIB token or project may clarify the intended target, but current evidence supports immediate mitigation actions. The domain remains active, and no takedown efforts have been observed as of the report date.
Stored source results
Recorded verdicts and infrastructure observations for this domain.
Copertura dei dati13 recorded checks
Pipeline di risposta alle minacce
Stato della lista di blocco pubblica
Analisi dei domini
Dettagli tecniciDNS, SAN SSL, timestamp
Riscontro delle informazioni sulle minacce · source references
Analisi di VirusTotal
Dati e relazioni esterneIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.