fluxat[.]pages[.]dev
“neux”
Resumo das evidências
This domain, fluxat.pages.dev, is actively engaged in credential harvesting through a fake login portal designed to mimic legitimate authentication interfaces. Analysis indicates the site employs social engineering tactics to deceive users into entering sensitive account credentials, which are then captured and exfiltrated to attacker-controlled infrastructure. The domain exhibits characteristics consistent with targeted phishing campaigns, including the use of obfuscated JavaScript and dynamic content loading to evade detection by automated security tools. The page title 'neux' does not correspond to any known legitimate service, further suggesting malicious intent. Infrastructure analysis reveals multiple high-risk indicators. The domain was registered on April 25, 2026, through Cloudflare, Inc., a registrar frequently leveraged by threat actors to obscure ownership and hosting details. It resolves to the IP address 172.66.47.120, located in California and associated with Cloudflare's content delivery network, which is commonly abused to mask the true origin of malicious traffic. As of the latest assessment, 3 out of 95 security vendors on VirusTotal have flagged this domain as malicious, a detection ratio that, while modest, aligns with emerging or low-volume threats. Additionally, the domain appears on one security blocklist, specifically PhishDestroy, confirming its classification as an active phishing resource. The SSL certificate, issued by Let's Encrypt (serial number E7), provides encryption but does not validate the legitimacy of the underlying content. Users who have visited fluxat.pages.dev or entered credentials on the site should take immediate remedial action. First, terminate all active sessions on the affected device and disconnect it from the network to prevent further data exfiltration. Reset passwords for any accounts accessed or entered on the site, prioritizing financial, email, and identity-related services. Enable multi-factor authentication (MFA) on all critical accounts to mitigate the risk of unauthorized access. Monitor account activity for signs of compromise, such as unrecognized logins or transactions. If sensitive data, such as payment information or government identifiers, was submitted, consider placing a fraud alert with relevant credit bureaus. Finally, scan the device using updated security software to detect and remove any malware or persistent threats that may have been installed during the interaction.
Data Coverage
Inteligência de segurança de rede
Pipeline de resposta a ameaças
Cobertura de listas de bloqueio
10 fontes externas monitoradas · instantâneo de 11/08/2026
10 fontes externas monitoradas Sem correspondência
Linha do tempo de detecção
-
Status do domínio
Acessível → Inacessível
Análise do VirusTotal
Análise de desempenho do site
Google PageSpeed Insights — mobile performance audit of fluxat.pages.dev · checked Apr 25, 2026
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo