bungeej[.]pages[.]dev
“Suspected phishing site | Cloudflare”
Observação armazenada
Contraste de títulos observado
Resumo das evidências
This domain, bungeej.pages.dev, is flagged as a credential theft operation targeting users of a widely recognized content delivery and security platform. Analysis indicates the site was designed to mimic legitimate login portals, tricking visitors into entering sensitive authentication details such as usernames, passwords, and potentially multi-factor authentication codes. The infrastructure leverages Cloudflare Pages hosting, a common tactic to exploit the perceived trustworthiness of the underlying service provider. There is no evidence of cryptocurrency wallet drainers or financial transaction redirection; the primary objective appears to be the unauthorized collection of user credentials for subsequent account compromise or lateral movement within target networks. Infrastructure analysis reveals several key indicators supporting this assessment. The domain was registered on March 28, 2026, suggesting either a typo-squatting attempt or a preemptive registration to evade detection. VirusTotal reports 0 detections out of 95 security engines, indicating the site has not yet been widely flagged by automated scanning systems. However, it appears on one security blocklist and is actively blocked by a specialized anti-phishing tool. The domain resolves to the IP address 172.66.45.34, which is part of a well-known anycast network range often associated with legitimate content delivery services. The SSL certificate is issued by Google Trust Services, providing an additional layer of perceived legitimacy to unsuspecting users. The Gridinsoft trust score of 0 out of 100 further corroborates the malicious classification. Users who visited bungeej.pages.dev or entered credentials on the site should take immediate remedial action. First, reset passwords for any accounts accessed from the same device or network, prioritizing those associated with the impersonated service or other high-value platforms. Enable multi-factor authentication if not already active, using app-based or hardware tokens rather than SMS-based methods. Monitor accounts for unauthorized activity, including login attempts, configuration changes, or data exfiltration. If corporate credentials were exposed, notify internal security teams to initiate incident response protocols, including credential rotation and network traffic analysis. The domain has been taken offline, but similar threats may persist; users should verify the authenticity of any unexpected login prompts, particularly those delivered via email or instant messaging.
Data Coverage
Pipeline de resposta a ameaças
Cobertura de listas de bloqueio
10 fontes externas monitoradas · instantâneo de 11/08/2026
10 fontes externas monitoradas Sem correspondência
Inteligência forense
Tecnologias
3 tecnologias identificadas com alta confiança
Análise do VirusTotal
Análise de desempenho do site
Google PageSpeed Insights — mobile performance audit of bungeej.pages.dev · checked Jun 26, 2026
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo