Phishing detection: vodafone-2rx.pages.dev
Vodafone Investigate
Domain
vodafone-2rx.pages.dev1 CT host on apex
IP
188.114.96.3
URL
https://vodafone-2rx.pages.dev
Cert
YE2
Phishunt analysis Beta
38
medium suspicion suspiciousheuristic risk score · not a probability
Why?
- +6.1 Google Safe Browsing
- +5.3 Keyword match
- +5.1 Site cluster
- +4.5 Brand in title
- +4.1 Brand in screenshot
- +3.7 Brand in domain label
- +3.4 Shared IP cluster
- +1.1 ASN reputation
- +1.1 No CSP header
- +1.1 No HSTS header
- +0.7 Brand in cert SAN
- +0.6 Suspicious TLD
- +0.5 Young certificate
- +0.5 Long domain
- +0.3 Free CA
- +0.1 Hyphens
- +0.1 Deep subdomain
20 signals fired · detector v3.0.0
AI analysis AIBeta
Credential harvesting
Site impersonates Vodafone on a Cloudflare Pages PaaS host and appears designed to harvest user credentials. Flagged by Google Safe Browsing as social engineering. Brand appears in both the domain label and page title, and security headers are absent.
Google Safe BrowsingBrand in domain labelPaaS host
AI-generated from stored detector signals - the AI never visited the site. · 2026-08-30 · confidence 80%
Domain & Network
Whois
Registrar
CloudFlare, Inc.
Network
IP
188.114.96.3
Country
United States
Hosting
Cloudflare, Inc.
ASN
AS13335
TLS Cert
YE2
External detection
Google Safe Browsing
GSB category: SOCIAL_ENGINEERING
CleanOpenPhish · PhishTank · TweetFeed · urlscan.io
Requests
Resources
Observables
Related websites
Report this phishing
Submit to blocklists
urlscan
VirusTotal
Whois
ipinfo
Greynoise