# 5eplays.co.com — SUSPICIOUS > PhishDestroy flags 5eplays.co.com as a crypto drainer phishing domain impersonating a gaming brand. Verify suspicious links immediately. ## Summary PhishDestroy identifies the domain 5eplays.co.com as an active crypto drainer phishing site operating under investigation since seed c93757. The threat involves malicious scripts designed to drain cryptocurrency wallets upon user interaction, specifically targeting gamers by mimicking legitimate gaming platforms. Current status remains active as forensic analysis continues to assess the full scope of the operation. This domain was flagged by 0 of 95 VirusTotal vendors despite resolving to IP 104.21.80.252 and holding a Google Trust Services SSL certificate. The registrar remains unverified in public databases, while the domain creation date shows recent registration patterns consistent with disposable phishing infrastructure. Blocklist counts stand at 0, with trust scores artificially inflated by the SSL certificate, indicating a sophisticated evasion technique targeting automated detection systems. The lack of vendor detections suggests either delayed signature updates or use of zero-day techniques. Users are advised to avoid interacting with 5eplays.co.com entirely. If exposure occurs, immediately revoke any connected wallet permissions and transfer remaining assets to a cold wallet. Report the domain to PhishDestroy for takedown while monitoring wallet addresses for outgoing transactions. Network administrators should block the IP 104.21.80.252 at the firewall level and inspect DNS logs for related domains sharing the same infrastructure. The absence of current detections makes this a high-priority threat requiring proactive mitigation. ## Threat Details - Verdict: SUSPICIOUS - Site status: unknown (HTTP ?) ## Domain Intelligence - Registrar: REGISTRAR_NOT_FOUND - IP: 104.21.80.252 ## Detection Status - VirusTotal: 0 vendors flagged - Google Safe Browsing: clean - Blocklists: 0 hits ## Evidence - Cloudflare Radar: https://radar.cloudflare.com/scan/14be69d0-7acc-414a-af1b-6e5e214e7fbd - PhishDestroy: https://phishdestroy.io/domain/5eplays.co.com/ - LLM endpoint: https://phishdestroy.io/domain/5eplays.co.com/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/5eplays.co.com/ Last updated: 2026-03-27