ca-portal-test[.]pages[.]dev
“Conditional Access Assessment Portal”
ca-portal-test.pages.dev — Não verificado. Representação da marca: Microsoft; Tipo de golpe: Credential Phishing. Resumo das evidências: VirusTotal 10/91 (alphaMountain.ai, BitDefender, CyRadar, ESET, Forcepoint ThreatSeeker); URLScan malicious verdict; PhishDestroy score 83/100. Registrador: Cloudflare.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
Analysis indicates that the domain ca-portal-test.pages.dev is an active phishing portal targeting Conditional Access authentication workflows. The domain was registered on June 15, 2026, through Cloudflare, Inc., and currently resolves to the IP address 188.114.96.3. The page title, 'Conditional Access Assessment Portal,' suggests an attempt to mimic enterprise identity and access management (IAM) systems, though the exact content and targeted brand remain unconfirmed due to lack of direct inspection. Infrastructure analysis reveals the use of Cloudflare hosting, HTTP/3, and HSTS, which may be employed to lend legitimacy or evade detection. The SSL certificate is issued by Google Trust Services, a common but not inherently malicious provider. As of July 12, 2026, the domain is flagged by 9 of 95 security vendors on VirusTotal and appears on one security blocklist, including PhishDestroy. The Gridinsoft trust score of 0/100 further supports its classification as malicious. Defenders should treat this domain as high-risk. The combination of a recently registered domain, Cloudflare hosting, and a page title indicative of IAM phishing warrants immediate blocking at the DNS or proxy level. Network logs should be reviewed for connections to 188.114.96.3 or the domain name, particularly from endpoints with access to enterprise authentication systems. No evidence of a specific phishing kit or targeted brand has been identified in available intelligence, so additional forensic analysis may be required if compromise is suspected.
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Tecnologias · 3 identified
HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 100% de confiançaCloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100% de confiançaHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% de confiançaAnálise do VirusTotal
Análise de desempenho do site
Google PageSpeed Insights — mobile performance audit of ca-portal-test.pages.dev · checked Jul 13, 2026
Evidências e relatórios externos
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo