Phishing detection: vodafone-2rx.pages.dev

Vodafone
https://vodafone-2rx.pages.dev Access site
Screenshot
Screenshot of vodafone-2rx.pages.dev
Investigate
Domain vodafone-2rx.pages.dev1 CT host on apex
URL https://vodafone-2rx.pages.dev
Phishunt analysis Beta
38 medium suspicion suspiciousheuristic risk score · not a probability
Why?
  • +6.1 Google Safe Browsing
  • +5.3 Keyword match
  • +5.1 Site cluster
  • +4.5 Brand in title
  • +4.1 Brand in screenshot
  • +3.7 Brand in domain label
  • +3.4 Shared IP cluster
  • +1.1 ASN reputation
  • +1.1 No CSP header
  • +1.1 No HSTS header
  • +0.7 Brand in cert SAN
  • +0.6 Suspicious TLD
  • +0.5 Young certificate
  • +0.5 Long domain
  • +0.3 Free CA
  • +0.1 Hyphens
  • +0.1 Deep subdomain
20 signals fired · detector v3.0.0
AI analysis AIBeta
Credential harvesting

Site impersonates Vodafone on a Cloudflare Pages PaaS host and appears designed to harvest user credentials. Flagged by Google Safe Browsing as social engineering. Brand appears in both the domain label and page title, and security headers are absent.

Google Safe BrowsingBrand in domain labelPaaS host
AI-generated from stored detector signals - the AI never visited the site. · 2026-08-30 · confidence 80%
Domain & Network
Whois
Registrar CloudFlare, Inc.
Network
Country United StatesUnited States
ASN AS13335
TLS Cert YE2
External detection Google Safe Browsing
GSB category: SOCIAL_ENGINEERING
CleanOpenPhish · PhishTank · TweetFeed · urlscan.io
Report this phishing
PaaS platform Cloudflare Pages
Registrar CloudFlare, Inc.

Tracked from 2026-08-30 17:25 UTC  ·  Last refreshed 2026-08-31 03:30 UTC