MALICIOUS — CRITICAL
pibrowser-activation[.]pages[.]dev
PhishDestroy identifies pibrowser-activation.pages.dev as a live phishing domain distributing a browser activation scam under investigation for malware distribution.
- VirusTotal
- 13/91
- Blocklists
- No stored match
- Disponibilità
- Ultimo attivo conosciuto · HTTP 200
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
pibrowser-activation.pages.dev — Ultimo attivo conosciuto (HTTP 200). Tipo di truffa: Fake Exchange. Riepilogo delle prove: VirusTotal 13/91 (alphaMountain.ai, BitDefender, CyRadar, ESET, Emsisoft); PhishDestroy score 100/100. Registrar: Cloudflare.
L’analisi dettagliata di PhishDestroy AI resta in inglese per preservare il rapporto forense originale.
Evidence Analysis
PhishDestroy identifies pibrowser-activation.pages.dev as a live phishing domain distributing a browser activation scam under investigation for malware distribution. This threat employs counterfeit activation prompts to harvest user credentials and potentially deploy malicious payloads.
This domain was flagged with 15/95 detections on VirusTotal despite active phishing distribution. Registered through Cloudflare, Inc., it resolves to IP 172.66.47.53 and operates under a Google Trust Services SSL certificate. The Campaign ID seed 0394e6 confirms this is part of an emerging campaign tracked since recent domain registration.
To mitigate this browser activation phishing scam, users should avoid interacting with any pibrowser-activation.pages.dev prompts and immediately report the domain. Organizations should block the IP 172.66.47.53 at the firewall level and update browser security policies to block Cloudflare Pages subdomains serving executable content. Security teams should monitor for similar phishing domains using seed 0394e6 patterns.
Copertura dei dati12 recorded checks
Informazioni sulla sicurezza di rete
Pipeline di risposta alle minacce
Stato della lista di blocco pubblica
Tecnologie · 11 identified
Open-source CMS powering over 40% of websites worldwide.
Open-source relational database management system.
Server-side scripting language designed for web development.
Fast, small JavaScript library simplifying HTML manipulation, event handling, and Ajax.
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Analisi di VirusTotal
Analisi delle prestazioni del sito
Google PageSpeed Insights — mobile performance audit of pibrowser-activation.pages.dev · checked Mar 28, 2026
Dati e relazioni esterneIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.