duck-purchase-website[.]pages[.]dev
“The Quack Token”
已存储的观测记录
观测到的标题差异
证据摘要
PhishDestroy identifies duck-purchase-website.pages.dev as an active banking phishing page that masquerades as a legitimate purchase portal to steal financial credentials. This domain leverages Cloudflare Pages hosting and Google Trust Services SSL to appear trustworthy at first glance, luring victims into entering sensitive banking details under the guise of completing a transaction. The page remains undetected by 0 security engines on VirusTotal—raising urgency for users to verify any unexpected payment links before interacting with them.
This domain was flagged by PhishDestroy on seed 335223 after analyzing its infrastructure. It was registered through Cloudflare, Inc. using a Pages.dev subdomain, a common tactic among phishing actors to rapidly deploy fraudulent portals with minimal cost. The site resolves to IP 172.66.47.155 and holds a valid SSL certificate issued by Google Trust Services, further enhancing its credibility. With zero detections on VirusTotal as of the latest scan, this site is actively evading detection systems, potentially exposing unsuspecting users who click without verification.
If you visited duck-purchase-website.pages.dev, immediately cease any input and close the browser tab. Do not enter any passwords, payment details, or personal information. Clear your browser cache and run a full antivirus scan. If you used payment details here, contact your bank immediately to report fraud and cancel affected cards. Save the full URL and any screenshots to report to your national cybercrime unit or platform provider. Stay vigilant—legitimate purchase sites rarely use free domains with hyphenated names and should be verified via official URLs.
Data Coverage
网络安全情报
威胁响应 Pipeline
阻止列表覆盖
监控中的外部数据源 10 个 · 已存快照 2026年8月13日
VirusTotal 分析
网站性能分析
Google PageSpeed Insights — mobile performance audit of duck-purchase-website.pages.dev · checked Mar 24, 2026
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。
检查任意域名
使用存储的阻止列表、WHOIS、DNS 和公共扫描证据进行威胁分析
立即扫描举报网络钓鱼
将可疑域名提交至我们的威胁数据库——保护社区
报告实时威胁动态
最近的网络钓鱼报告和观察到的可用性变化
监控