MALICIOUS — CRITICAL
networkchains-8wb.pages.dev için kimlik avı ve güvenlik kontrolü
networkchains-8wb[.]
PhishDestroy identifies a credential-harvesting campaign hosted at networkchains-8wb.pages.dev that mimics corporate login portals to steal Microsoft 365 credentials.
- VirusTotal
- 3/91
- Blocklists
- No stored match
- Kullanılabilirlik
- Bilinen son aktif · HTTP 200
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
networkchains-8wb.pages.dev — Bilinen son aktif (HTTP 200). Marka kimliğine bürünme: Microsoft; Dolandırıcılık türü: Brand Impersonation. Kanıt özeti: VirusTotal 3/91 (alphaMountain.ai, Fortinet, Sophos); PhishDestroy score 74/100. Kayıt kuruluşu: Cloudflare.
Özgün adli kaydı korumak için aşağıdaki ayrıntılı PhishDestroy AI analizi İngilizce bırakılmıştır.
Evidence Analysis
PhishDestroy identifies a credential-harvesting campaign hosted at networkchains-8wb.pages.dev that mimics corporate login portals to steal Microsoft 365 credentials. The page is served over HTTPS via Cloudflare Pages, resolving to IP 188.114.97.3 and has evaded detection by all 95 VirusTotal engines so far. Visitors entering any credentials are immediately transmitted to attacker-controlled infrastructure, risking account takeover and lateral movement in cloud environments.
PhishDestroy’s investigation confirms this domain was registered through Cloudflare, Inc. and shows zero detections on VirusTotal as of the latest scan. The page was built on Cloudflare’s Pages platform and currently points to the Cloudflare IP range 188.114.97.3 with no additional infrastructure enrichment yet visible. Because Cloudflare Pages allows rapid deployment of spoofed login pages, threat actors can iterate campaigns faster than traditional hosting providers, increasing the likelihood of successful credential collection before detection occurs.
If you visited networkchains-8wb.pages.dev and entered any credentials, assume your Microsoft 365 or related corporate account has been compromised. Immediately change your password using a known-clean device, enable multi-factor authentication if not already enabled, and report the incident to your IT security team. Scan recent sign-in logs for anomalous activity and revoke any unrecognized sessions or OAuth tokens. Do not reuse the exposed password on other systems. Forward the URL or any screenshots to your security team for forensic analysis and indicator-of-compromise extraction.
Stored source results
Recorded verdicts and infrastructure observations for this domain.
Veri kapsamı12 recorded checks
Ağ Güvenliği İstihbaratı
Tehdit Müdahale Pipeline
Genel Engelleme Listesi Durumu
VirusTotal Analizi
Arşivlenmiş Kanıtlar
Site Performans Analizi
Google PageSpeed Insights — mobile performance audit of networkchains-8wb.pages.dev · checked Mar 26, 2026
Kanıtlar ve Dış RaporlarIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.