wwwworldlibertyfinancialcom[.]pages[.]dev
wwwworldlibertyfinancialcom.pages.dev — Контент недоступний. Уособлення бренду: MetaMask. Зведення доказів: VirusTotal 12/91 (ChainPatrol, alphaMountain.ai, BitDefender, CyRadar, ESET); 3 external blocklist matches (MetaMask, ScamSniffer, SEAL); PhishDestroy score 86/100. Реєстратор: Cloudflare Pages.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
Analysis indicates that the domain wwwworldlibertyfinancialcom.pages.dev was registered on June 05, 2026 via the Cloudflare Pages service. The site resolves to the IP address 172.66.47.67, which is part of Cloudflare's edge network. Within three weeks of registration the domain has been listed on four independent security blocklists, specifically PhishDestroy, MetaMask, ScamSniffer, and SEAL, reflecting rapid detection by anti‑phishing tooling. VirusTotal has recorded detections from twelve of ninety‑one scanning engines, confirming that the payload or URL pattern is recognized as malicious by a subset of reputable vendors. The threat classification supplied is “generic phishing” and the risk level is marked as high, with the campaign status still active as of the report date, July 29, 2026.
The available evidence does not include details such as SSL certificate properties, HTTP response codes, page title, or any observed landing‑page content, leaving those aspects unverified. Consequently, defenders cannot assess whether the site serves a credential‑harvesting form, redirects to additional payloads, or employs any evasion techniques beyond the observed blocklist listings. The lack of publicly disclosed page content also prevents confirmation of any targeted brand or specific social‑engineering narrative. Given the current indicators, security operations should treat any traffic to wwwworldlibertyfinancialcom.pages.dev as malicious.
Defensive measures should include immediate blocking at perimeter firewalls, DNS filtering, and proxy enforcement, leveraging the known blocklist identifiers. Endpoint protection solutions that reference VirusTotal detection counts should be updated to flag the domain, and any existing email or web gateway rules that reference the listed blocklists (PhishDestroy, MetaMask, ScamSniffer, SEAL) should be verified for coverage. Continuous monitoring of the IP address 172.66.47.
Розвіддані з мережевої безпеки
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Аналітика доменів
Технічні деталіDNS, SAN-адреси SSL, мітки часу
Аналіз VirusTotal
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога