vro1lxi[.]pages[.]dev
Verifica phishing e sicurezza per vro1lxi.pages.dev
“HIGHER | Presale”
vro1lxi.pages.dev — Ultimo attivo conosciuto (HTTP 200). Tipo di truffa: Fake Airdrop. Riepilogo delle prove: VirusTotal 3/91 (alphaMountain.ai, Gridinsoft, LevelBlue); 3 external blocklist matches (MetaMask, ScamSniffer, SEAL); PhishDestroy score 84/100. Registrar: Cloudflare.
L’analisi dettagliata di PhishDestroy AI resta in inglese per preservare il rapporto forense originale.
Evidence Analysis
vro1lxi.pages.dev represents a currently active domain engaged in a generic phishing campaign, as classified under investigation by SOC monitoring systems. vro1lxi.pages.dev was observed distributing phishing content designed to mimic well-known service providers, aiming to deceive users into disclosing sensitive authentication details. According to VirusTotal analysis conducted on the unique seed f56bbd, the domain remains undetected by 4 out of 95 security vendors as of the latest scan, despite its malicious hosting patterns. The infrastructure leverages Cloudflare Pages as the registrar, resolving to IP address 188.114.96.3, which is linked to Google Trust Services for SSL certification. No historical blocklist entries or reputation penalties are currently registered against this domain, indicating a potentially emergent threat with minimal prior exposure across threat intelligence platforms. While the immediate risk is categorized as under investigation, the absence of detections should not be interpreted as safety assurance due to the dynamic nature of phishing campaigns. The domain’s use of Cloudflare’s infrastructure complicates defensive blocking efforts, as legitimate services also rely on the same CDN. Organizations and end-users are advised to implement strict URL inspection policies, deny access to pages.dev subdomains via network controls, and prioritize user awareness training emphasizing verification of domain authenticity before credential submission. Monitoring for new IOCs, such as associated IP resolutions or certificate changes, is strongly recommended to preempt potential escalation.
Copertura dei dati12 recorded checks
Pipeline di risposta alle minacce
Stato della lista di blocco pubblica
Analisi di VirusTotal
Analisi delle prestazioni del sito
Google PageSpeed Insights — mobile performance audit of vro1lxi.pages.dev · checked Apr 6, 2026
Dati e relazioni esterneIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.