dct-1t9.pages.dev
Category: Phishing
- Don't sign in or pay here. Close it. If you typed a password, change it where you normally use it.
- Already visited? Check your device. A free scan shows whether anything was installed.
- Stop the next one. Combo Cleaner's web protection blocks phishing and scam sites before they load.
Combo Cleaner is PCrisk's own anti-malware tool, owned by RCS LT. Free to scan; removing what it finds needs a licence (7-day free trial).
Description of dct-1t9.pages.dev
The domain dct-1t9.pages.dev is a subdomain hosted on Cloudflare Pages, a free platform that developers use to deploy static websites and web applications. Because Cloudflare Pages assigns auto-generated subdomains like this one to user-created projects, the site itself is not operated by Cloudflare but by an independent third party who has published content under Cloudflare's shared hosting infrastructure.
The domain's registration record actually reflects Cloudflare's own registrar and nameserver information (a common characteristic of *.pages.dev sites), rather than any dedicated organizational owner. This makes it difficult to determine who is truly behind the content without inspecting the live page. The naming convention "dct-1t9" appears to be a randomly generated project identifier rather than a meaningful brand name, which is typical of temporary or disposable web projects.
Given the generic subdomain structure and lack of categorization, this page likely represents a small or short-lived project, campaign, or test deployment rather than an established, publicly recognized brand or business.
Safety Assessment for dct-1t9.pages.dev
At the time of this scan, 4 out of 91 security engines flagged this domain specifically for phishing activity, with malware classification labels including "phishing" and generic "malicious" designations from multiple independent engines. While the majority of engines did not flag the site, this level of consensus across several unrelated security vendors is a meaningful signal that should not be dismissed, particularly because phishing detections (rather than vague heuristic tags) tend to be more reliable indicators of active abuse.
Additional scan data shows mixed signals: while Google Safe Browsing and most blacklist/threat-database providers reported the domain as clean, one database (QBMA) listed it under a generic malicious-object classification, and the domain's IP address was also found listed on one mail/IP-reputation blocklist (SURBL). This DNSBL listing is a weaker signal that primarily reflects email or IP reputation rather than direct confirmation of malicious website content, so it was weighted lightly in this assessment. A malware scan of the site's files did not turn up any explicitly flagged files, though a generic "suspicious object" label was applied to some Cloudflare-related resource files, which by itself is a low-confidence pattern match.
Taken together - direct phishing detections from multiple reputable engines combined with a malicious listing on at least one additional threat database - this collection of findings is more concerning than an isolated heuristic flag would be. Based on these findings, this website may pose potential risks to visitors, and caution is advised, especially around any forms, login prompts, or download requests the page may present.
Technical Description
The site is served over a valid SSL/TLS certificate issued by Google Trust Services, expiring in December 2026, and is hosted entirely on Cloudflare's global network (server location reported as Toronto, Canada), which also provides the domain's nameservers. DNSSEC is not enabled for this domain. The hosting setup (Cloudflare Pages) means the underlying server infrastructure is shared and abstracted, making it harder to trace the responsible content owner directly from infrastructure metadata alone.
The presence of Cloudflare's own error-page stylesheets and challenge/turnstile scripts among the flagged external resources suggests the site may be leveraging Cloudflare's standard security challenge or error-handling framework, which is common on both legitimate and malicious Cloudflare-hosted pages. No iframes were detected, and the small number of external links/domains referenced are primarily Cloudflare's own infrastructure domains.
Share your experience with this website. Was it safe? Did you encounter any issues?