MALICIOUS — CRITICAL
Phishing- und Sicherheitsprüfung für memerreum.pages.dev
memerreum[.]
Analysis of memerreum.pages.dev indicates an active high‑risk phishing campaign targeting cryptocurrency investors.
- VirusTotal
- 11/91
- Blocklists
- No stored match
- Verfügbarkeit
- Letzter bekanntermaßen aktiv · HTTP 200
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
memerreum.pages.dev — Letzter bekanntermaßen aktiv (HTTP 200). Markenidentität: Genericcrypto; Betrugstyp: Crypto Drainer. Zusammenfassung der Beweislage: VirusTotal 11/91 (alphaMountain.ai, BitDefender, ESET, Fortinet, G-Data); URLScan malicious verdict; PhishDestroy score 98/100. Registrar: Cloudflare.
Die ausführliche Analyse von PhishDestroy AI bleibt auf Englisch, damit der ursprüngliche forensische Bericht unverändert bleibt.
Evidence Analysis
Analysis of memerreum.pages.dev indicates an active high‑risk phishing campaign targeting cryptocurrency investors. The domain was registered on 29 April 2026 through Cloudflare, Inc., and is hosted behind Cloudflare’s network (IP 172.66.47.179, geolocated to Canada). DNS resolution uses the authoritative nameservers faye.ns.cloudflare.com and reese.ns.cloudflare.com, and the site presents a valid Google Trust Services certificate (WE1) with HSTS enabled and HTTP/3 support. The landing page returns HTTP 200 and carries the title “Memereum Presale Portal”, suggesting an attempt to lure victims into a crypto presale scam. Technological fingerprints include Statcounter analytics and Cloudflare services. VirusTotal has reported six detections out of ninety‑one scanners, and the site is listed on one external blocklist and has been blocked by PhishDestroy. Gridinsoft assigns a trust score of 0 / 100, reinforcing the malicious classification. Current evidence confirms the site functions as a crypto drainer phishing vector; however, the specific content of the page and any credential‑stealing mechanisms have not been publicly disclosed. Defenders should block the domain and its associated IP at perimeter and DNS layers, monitor for any related DNS queries, and consider adding the host to internal threat intel feeds. Ongoing observation is advised to capture any changes in infrastructure or payload delivery.
Stored source results
Recorded verdicts and infrastructure observations for this domain.
Datenabdeckung12 recorded checks
Erkenntnisse zur Netzwerksicherheit
Pipeline zur Reaktion auf Sicherheitsbedrohungen
Status der öffentlichen Sperrliste
Technologien · 4 identified
Analytics / tracking service — collects visitor behavior data for the site owner.
www.statcounter.com 100 % KonfidenzHTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 100 % KonfidenzCloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100 % KonfidenzHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100 % KonfidenzVirusTotal-Analyse
Website-Performanceanalyse
Google PageSpeed Insights — mobile performance audit of memerreum.pages.dev · checked Apr 29, 2026
Nachweise und externe BerichteIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Wenn Sie Kontoanmeldeinformationen, persönliche oder Zahlungsinformationen eingegeben oder eine Datei von dieser Domain heruntergeladen haben, ergreifen Sie sofort Maßnahmen. Nachfolgend finden Sie Ressourcen, die Ihnen helfen, den Vorfall zu melden und sich zu schützen.
Melden Sie sich bei Ihren örtlichen Behörden
Wählen Sie Ihr Land aus, um Offizielle Kontakte im Bereich Cyberkriminalität oder einen Beschwerdeentwurf erstellen → zu erhalten.