Phishing detection: vodafone-9r2.pages.dev
Vodafone Investigate
Domain
vodafone-9r2.pages.dev1 CT host on apex
IP
172.66.44.91
URL
https://vodafone-9r2.pages.dev
Cert
Sectigo Limited
Phishunt analysis Beta
30
low suspicionheuristic risk score · not a probability
Why?
- +5.3 Keyword match
- +5.1 Site cluster
- +5.1 urlscan.io
- +4.1 Brand in screenshot
- +3.7 Brand in domain label
- +2.0 Young domain
- +1.1 ASN reputation
- +1.1 No CSP header
- +1.1 No HSTS header
- +0.7 Brand in cert SAN
- +0.6 Suspicious TLD
- +0.5 Long domain
- +0.1 Hyphens
- +0.1 External scripts
- +0.1 Deep subdomain
18 signals fired · detector v3.0.0
AI analysis AIBeta
Credential harvesting
Impersonates Vodafone on a Cloudflare Pages free subdomain, confirmed malicious by urlscan.io. The certificate SAN embeds the Vodafone brand and the site lacks outbound links to the legitimate company, indicating credential or account data harvesting.
Brand in cert SANPaaS hosturlscan.io
AI-generated from stored detector signals - the AI never visited the site. · 2026-08-31 · confidence 82%
Domain & Network
Whois
Registrar
CloudFlare, Inc.
Network
IP
172.66.44.91
Country
United States
Hosting
Cloudflare, Inc.
ASN
AS13335
TLS Cert
Sectigo Limited
External detection
urlscan.io
CleanGoogle Safe Browsing · OpenPhish · PhishTank · TweetFeed
Requests
Resources
Observables
Related websites
Report this phishing
Submit to blocklists
urlscan
VirusTotal
Whois
ipinfo
Greynoise