lofai-connect[.]pages[.]dev
“LofaiApp - CRM WhatsApp Oficial | Automação de Atendimento Multicanal”
lofai-connect.pages.dev — Não verificado. Tipo de golpe: Generic Phishing. Resumo das evidências: VirusTotal 0/91; PhishDestroy score 68/100. Registrador: Cloudflare.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
This domain is currently under investigation for credential theft through WhatsApp brand impersonation. The site presents itself as an official CRM solution for WhatsApp automation, specifically targeting users seeking multichannel customer service tools. The fraudulent nature is evident through the unauthorized use of WhatsApp's branding in both the page title and content structure, designed to harvest login credentials from business users. Analysis indicates the domain lofai-connect.pages.dev was registered through Cloudflare, Inc. on April 01, 2026, with an anomalous future creation date suggesting potential domain spoofing. The site resolves to IP address 188.114.96.3, hosted in Canada under Cloudflare infrastructure. Security telemetry shows 0/95 detections on VirusTotal, though it appears on one blocklist maintained by PhishDestroy. The SSL certificate is issued by Google Trust Services (WE1), providing a false sense of legitimacy while the domain remains active and unflagged by most security vendors. Mitigation requires immediate blocking of the domain and associated IP address across all network security controls. Organizations should implement additional verification for any WhatsApp-related business tools, particularly those offering automation services. Security teams are advised to monitor for credential submission attempts to this domain and conduct password resets for any accounts potentially exposed. Given the brand impersonation vector, user awareness training should emphasize verification of official WhatsApp partnerships and domain legitimacy before credential submission.
Inteligência de segurança de rede
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Tecnologias · 3 identified
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Análise do VirusTotal
Análise de desempenho do site
Google PageSpeed Insights — mobile performance audit of lofai-connect.pages.dev · checked Apr 1, 2026
Análise da configuração do site
Evidências e relatórios externos
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo