MALICIOUS — CRITICAL
Is source-desktop-faq.pages.dev a Crypto Drainer Scam?
source-desktop-faq[.]
PhishDestroy identifies source-desktop-faq.pages.dev as an active crypto drainer operating under the guise of a legitimate FAQ support page.
- VirusTotal
- 14/91
- Blocklists
- No stored match
- Verfügbarkeit
- Erreichbar · Zugang eingeschränkt · HTTP 403
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
source-desktop-faq.pages.dev — Erreichbar · Zugang eingeschränkt (HTTP 403). Markenidentität: Ledger; Betrugstyp: Crypto Drainer. Zusammenfassung der Beweislage: VirusTotal 14/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, CyRadar, ESET); URLScan malicious verdict; PhishDestroy score 97/100. Registrar: Cloudflare.
Die ausführliche Analyse von PhishDestroy AI bleibt auf Englisch, damit der ursprüngliche forensische Bericht unverändert bleibt.
Evidence Analysis
PhishDestroy identifies source-desktop-faq.pages.dev as an active crypto drainer operating under the guise of a legitimate FAQ support page. This domain exhibits classic red flags associated with cryptocurrency theft, where unsuspecting users are lured into connecting their wallets under false pretenses. The malicious infrastructure is designed to exfiltrate funds through deceptive transaction requests, making it a high-risk threat to cryptocurrency users who may mistake it for an official help desk portal.
Technical analysis of this domain reveals concerning indicators of compromise. VirusTotal currently flags the domain with 0 detections out of 95 antivirus engines, indicating it has yet to be widely recognized by security vendors. Registered through Cloudflare, Inc., the domain leverages Cloudflare Pages for hosting, adding a layer of obfuscation commonly used by threat actors to evade detection. The SSL certificate, issued by Google Trust Services, provides an air of legitimacy, while the underlying IP address (188.114.96.3) is associated with known malicious activity. Additionally, this domain has not yet been documented on major threat intelligence blocklists, further emphasizing the need for proactive monitoring and user vigilance.
If you have interacted with source-desktop-faq.pages.dev, particularly by connecting a cryptocurrency wallet or entering sensitive credentials, immediate action is required. Disconnect your wallet from the site immediately and revoke any unauthorized permissions granted during the session. Scan your device for malware using verified security tools and consider transferring remaining funds to a new wallet with a different seed phrase. Report the incident to PhishDestroy to help prevent further exploitation of this domain. Avoid revisiting the site, as it poses an ongoing risk to cryptocurrency assets.
Stored source results
Recorded verdicts and infrastructure observations for this domain.
Datenabdeckung12 recorded checks
Erkenntnisse zur Netzwerksicherheit
Pipeline zur Reaktion auf Sicherheitsbedrohungen
Status der öffentlichen Sperrliste
Technologien · 3 identified
HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 100 % KonfidenzCloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100 % KonfidenzHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100 % KonfidenzVirusTotal-Analyse
Website-Performanceanalyse
Google PageSpeed Insights — mobile performance audit of source-desktop-faq.pages.dev · checked Apr 29, 2026
Nachweise und externe BerichteIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Wenn Sie Kontoanmeldeinformationen, persönliche oder Zahlungsinformationen eingegeben oder eine Datei von dieser Domain heruntergeladen haben, ergreifen Sie sofort Maßnahmen. Nachfolgend finden Sie Ressourcen, die Ihnen helfen, den Vorfall zu melden und sich zu schützen.
Melden Sie sich bei Ihren örtlichen Behörden
Wählen Sie Ihr Land aus, um Offizielle Kontakte im Bereich Cyberkriminalität oder einen Beschwerdeentwurf erstellen → zu erhalten.