vro1qi5xe[.]pages[.]dev
“Welcome to Polygon - Layer3”
ملاحظة محفوظة
تباين العناوين المرصود
ملخص الأدلة
This domain, vro1qi5xe.pages.dev, is flagged for brand impersonation targeting Polygon, a prominent blockchain network. Analysis indicates the site masqueraded as a legitimate Layer3 interface under the title 'Welcome to Polygon - Layer3,' likely designed to deploy a crypto drainer mechanism. The infrastructure leveraged Cloudflare Pages, a common hosting choice for threat actors due to its ephemeral nature and ease of deployment. No explicit drainer kit signatures were identified in initial scans, but the domain's structure and branding align with known crypto theft campaigns observed in recent months. Technical indicators reveal a VirusTotal detection score of 0/95, suggesting the domain had not yet been flagged by antivirus engines at the time of analysis. The domain was registered through Cloudflare, Inc. on December 16, 2025, and resolved to the IP address 172.66.44.76, a Cloudflare-operated endpoint. The SSL certificate was issued by Google Trust Services, a legitimate provider, which may have contributed to evading initial suspicion. Despite the clean VirusTotal record, the domain appeared on 5 security blocklists, including MetaMask, PhishDestroy, SEAL, ScamSniffer, and OISD, indicating prior detection by specialized crypto threat intelligence feeds. The site employed HTTP/3 and HSTS, technologies often used to enhance performance and security but also adopted by malicious actors to lend credibility to fraudulent pages. As of the latest assessment, the domain has been taken offline, likely following reports from security researchers or automated takedown mechanisms. However, the risk of re-emergence remains, as threat actors frequently rotate domains or repurpose infrastructure. Users who interacted with the site are advised to revoke any connected wallet permissions immediately and monitor for unauthorized transactions. Organizations should update blocklists to include this domain and its associated indicators, such as the IP address and SSL certificate details. Continuous monitoring of Cloudflare Pages-hosted domains with similar naming patterns is recommended, as this infrastructure remains a favored vector for crypto-related fraud.
Data Coverage
مسار الاستجابة للتهديدات Pipeline
تغطية قوائم الحظر
١٠ مصادر خارجية مراقبة · لقطة محفوظة 11/08/2026
٧ مصادر خارجية مراقبة لا تطابق
التقنيات
حُدّدت ٤ تقنيات عالية الثقة
تحليل VirusTotal
تحليل أداء الموقع
Google PageSpeed Insights — mobile performance audit of vro1qi5xe.pages.dev · checked Jun 26, 2026
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب