taprootwitchesholder[.]pages[.]dev
“Taproot Witches holder”
Observação armazenada
Contraste de títulos observado
Resumo das evidências
PhishDestroy identifies taprootwitchesholder.pages.dev as an active generic phishing domain currently under investigation for credential harvesting and fraudulent fund diversion. The domain leverages the Cloudflare Pages platform, exploiting its legitimate hosting infrastructure to evade detection and add an air of credibility to malicious web content. No specific brand or drainer kit has been publicly attributed to this campaign as of this report, though the use of Pages.dev subdomains suggests an opportunistic approach targeting users expecting legitimate Cloudflare-hosted tools or services. This domain resolves to IP address 172.66.45.48 via Cloudflare's infrastructure and is registered through Cloudflare, Inc. The SSL certificate is issued by Google Trust Services, further enhancing its appearance of legitimacy. As of the latest retrieval, VirusTotal shows 0 detections out of 95 engines, indicating it remains under the radar of mainstream security tools. The domain is currently active and not yet flagged by Google Safe Browsing (GSB) or widely distributed blocklists, though monitoring systems are likely tracking its movements closely. No creation date is provided in available datasets, but the Pages.dev subdomain structure suggests recent deployment. The current status of taprootwitchesholder.pages.dev is active and under active monitoring by cybersecurity research teams including PhishDestroy. Immediate response actions involve blocking the domain at the network and DNS levels, and sharing IOCs (Indicators of Compromise) with threat intelligence platforms to prevent propagation. While the risk level is currently classified as under_investigation, the lack of detections and use of trusted infrastructure pose an elevated threat to unsuspecting users. Users are strongly advised to avoid accessing this domain, verify URLs before interaction, and report any encounters to their security teams or through platforms like PhishDestroy for further analysis. Remaining risk includes potential expansion into broader phishing campaigns or integration into malware delivery chains.
Data Coverage
Pipeline de resposta a ameaças
Cobertura de listas de bloqueio
10 fontes externas monitoradas · instantâneo de 11/08/2026
7 fontes externas monitoradas Sem correspondência
Tecnologias
9 tecnologias identificadas com alta confiança
Análise do VirusTotal
Análise de desempenho do site
Google PageSpeed Insights — mobile performance audit of taprootwitchesholder.pages.dev · checked Apr 29, 2026
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo