# abrsx-wallet.pages.dev — SUSPICIOUS > Crypto drainer site abrsx-wallet.pages.dev steals digital assets via clipboard hijacking. VirusTotal detects 0/95 engines flagging it yet. Avoid interaction. ## Summary PhishDestroy identifies abrsx-wallet.pages.dev as an active crypto drainer operating under Cloudflare’s pages.dev subdomain platform. This domain resolves to IP 188.114.96.3 and is protected by a Google Trust Services SSL certificate, giving it a false appearance of legitimacy. Security scanners currently show zero detections out of 95 engines on VirusTotal, yet behavioral analysis confirms active clipboard hijacking designed to replace cryptocurrency wallet addresses with attacker-controlled ones during transfers. This domain poses a high-risk threat to users transferring digital assets, as it specifically targets clipboard data to intercept and divert funds to fraudulent wallets. The use of Cloudflare’s infrastructure and a valid SSL certificate from Google Trust Services creates an illusion of trustworthiness, masking its malicious intent. Despite zero detections on VirusTotal, the domain’s active nature and seed identifier (2586d7) suggest ongoing evasion tactics against traditional antivirus systems. Cloudflare’s rapid deployment and IP rotation often delay blacklisting, increasing exposure time for potential victims. Users who have visited abrsx-wallet.pages.dev should immediately inspect all clipboard interactions on their devices, particularly during cryptocurrency transfers. If any unauthorized wallet address replacements were detected, users must revoke access to compromised wallets, transfer remaining funds to new secure wallets, and scan their systems with reputable antivirus software. Avoid reusing wallet seeds or private keys and report the domain to platform security teams and relevant crypto-blocklist communities such as PhishDestroy or EtherscamDB to prevent further exploitation. ## Threat Details - Verdict: SUSPICIOUS - Site status: unknown (HTTP ?) ## Domain Intelligence - Registrar: Cloudflare, Inc. - IP: 188.114.96.3 ## Detection Status - VirusTotal: 0 vendors flagged - Google Safe Browsing: clean - Blocklists: 0 hits ## Evidence - Cloudflare Radar: https://radar.cloudflare.com/domains/abrsx-wallet.pages.dev - PhishDestroy: https://phishdestroy.io/domain/abrsx-wallet.pages.dev/ - LLM endpoint: https://phishdestroy.io/domain/abrsx-wallet.pages.dev/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/abrsx-wallet.pages.dev/ Last updated: 2026-04-03