MALICIOUS — HIGH
build-client[.]pages[.]dev
This domain is flagged as a credential harvesting phishing site targeting users through deceptive login interfaces.
- VirusTotal
- 0/91
- Blocklists
- 2 · MetaMask, SEAL
- Disponibilidade
- Conteúdo indisponível · HTTP 502
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
build-client.pages.dev — Conteúdo indisponível (HTTP 502). Tipo de golpe: Credential Phishing. Resumo das evidências: VirusTotal 0/91; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 66/100. Registrador: Cloudflare.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
Evidence Analysis
build-client.pages.dev — Credential Harvesting Phishing Site
build-client.pages.dev is an active credential harvesting phishing domain hosted on Cloudflare, resolving to 172.66.44.133.
This domain is flagged as a credential harvesting phishing site targeting users through deceptive login interfaces. Analysis indicates it is designed to mimic legitimate authentication portals, tricking visitors into submitting usernames, passwords, and potentially multi-factor authentication codes. The site remains operational and poses a direct risk to individuals and organizations relying on cloud-based or enterprise authentication systems. Infrastructure analysis reveals the domain is registered through Cloudflare, Inc., and currently resolves to the IP address 172.66.44.133. As of the latest scan, VirusTotal reports zero detections across 95 security engines, suggesting the phishing content has not yet been widely identified or classified. The domain remains active, with no observed takedown or mitigation efforts in place. The lack of prior detection increases the likelihood of successful compromise for unsuspecting users. Users who have visited build-client.pages.dev or entered credentials on the site should immediately revoke any submitted passwords and enable multi-factor authentication on associated accounts. Network administrators are advised to block the domain and IP address 172.66.44.133 at the perimeter level. Monitor for unusual authentication attempts or unauthorized access originating from affected accounts. If corporate credentials were exposed, initiate incident response protocols, including forced password resets and log reviews for anomalous activity. Report the domain to relevant abuse channels for further investigation and takedown.
Stored source results
Recorded verdicts and infrastructure observations for this domain.
Cobertura dos dados12 recorded checks
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Análise do VirusTotal
Evidências e relatórios externosIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.