billcipherwld[.]pages[.]dev
Verificação de phishing e segurança de billcipherwld.pages.dev
“Bill Cipher”
billcipherwld.pages.dev — Último ativo conhecido (HTTP 200). Resumo das evidências: VirusTotal 2/91 (Forcepoint ThreatSeeker, Gridinsoft); 1 external blocklist match (ScamSniffer); PhishDestroy score 76/100. Registrador: Cloudflare Pages.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
This report covers the domain billcipherwld.pages.dev as of August 02, 2026. The domain is currently flagged as a generic phishing threat and is under investigation. It is actively resolving and has been blocked by the PhishDestroy security service, which indicates a level of community or vendor distrust. The domain appears on one security blocklist, confirming that at least one independent source has identified it as malicious or suspicious. VirusTotal has scanned the domain with 91 vendors, and none of them currently flag it as malicious.
However, the absence of detections is not proof of safety; many phishing domains evade detection at first scan or are only flagged after wider reporting. No other intelligence is available at this time. The exact content hosted on the domain has not yet been analysed, so the specific brand impersonated, page layout, or scam mechanism remains unknown. The domain is hosted on the pages.dev subdomain infrastructure, which is a common service used by attackers for quick, disposable phishing pages, though this alone is not conclusive of malicious intent. Defenders should treat this domain with caution.
Recommended actions include monitoring the domain for changes in DNS or hosting, submitting it to additional threat intelligence platforms, and reviewing any internal logs for connections to this host. If users have interacted with the site, they should be advised to change credentials and monitor for account compromise. The low detection rate among vendors suggests that this may be a newer or less widely distributed campaign, and the domain could escalate in severity as more data is collected. Further investigation is required to determine the true nature of the threat, but the existing blocklist presence and the active status warrant continued surveillance and defensive blocking. The seed for this analysis is 16a082.
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Tecnologias · 5 identified
Wix provides cloud-based web development services, allowing users to create HTML5 websites and mobile sites.
www.wix.com 100% de confiançaReact is an open-source JavaScript library for building user interfaces or UI components.
reactjs.org 100% de confiançaHTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 100% de confiançaCloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100% de confiançaHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% de confiançaAnálise do VirusTotal
Evidências arquivadas
Evidências e relatórios externos
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo