# PhishDestroy threat dossier — balaancer-dex-us.pages.dev ================================================================ Fetched: 2026-05-04 03:05:03 UTC Canonical: https://phishdestroy.io/domain/balaancer-dex-us.pages.dev/ ## VERDICT ---------------------------------------------------------------- CRITICAL THREAT — DO NOT VISIT Composite threat score: 100/100 (PhishDestroy scoring — see methodology below) Scam classification: Impersonation Targeted brand: Balancer ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 1/91 security vendors flagged this domain Flagging vendors: LevelBlue ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 188.114.97.3 (CA, Toronto) ASN: AS13335 Cloudflare, Inc. Hosting org: CloudFlare, Inc. Registrar: Cloudflare, Inc. Nameservers: celine.ns.cloudflare.com, dylan.ns.cloudflare.com Registered: 2026-05-01 Page title: Balancer DEX - Smart DeFi Liquidity HTTP response: 200 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Google Trust Services / WE1 Expires: 2026-07-29 Status: INVALID chain Fingerprint: f07b48104247b3ed7a92a56cc038c9e5fb0a5284e902c2a17447f34bb6c74333 ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-05-01 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-05-01 10:43:48 UTC (by PhishDestroy tracker) Last verified: 2026-05-03 13:40:05 UTC Current status: ACTIVE / observable ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019de27b-9555-72fd-a070-aaafa5a34f43/ Wayback Machine: https://web.archive.org/web/*/balaancer-dex-us.pages.dev crt.sh CT logs: https://crt.sh/?q=%25.balaancer-dex-us.pages.dev Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=balaancer-dex-us.pages.dev AlienVault OTX: https://otx.alienvault.com/indicator/domain/balaancer-dex-us.pages.dev URLhaus: https://urlhaus.abuse.ch/host/balaancer-dex-us.pages.dev/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-05-01 10:45:43 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] PhishDestroy identifies balaancer-dex-us.pages.dev as an active cryptocurrency exchange phishing domain designed to trick users into connecting their digital wallets and stealing crypto funds. The site masquerades as a legitimate decentralized exchange, luring victims with promises of low fees or exclusive tokens. Once a victim connects a wallet through the embedded interface, the operators immediately drain the wallet of all supported assets. This type of scam is commonly distributed via social media ads, spoofed Discord servers, or phishing emails that mimic legitimate DeFi projects. This domain was flagged by PhishDestroy after VirusTotal scanning revealed that only 1 out of 95 security vendors currently detects the threat. The site is served from Cloudflare Pages at IP address 188.114.97.3, and its SSL certificate is issued by Google Trust Services, which adds a veneer of legitimacy. The domain leverages Cloudflare’s free hosting and trusted SSL to bypass browser warnings. Based on telemetry and campaign patterns, the infrastructure appears to have been activated very recently, increasing the risk of newly compromised users falling victim. If you visited or used balaancer-dex-us.pages.dev, disconnect your wallet immediately using your wallet’s built-in connection manager or browser extension. Revoke any token approvals via reputable tools like revoke.cash or Etherscan’s approval checker. Scan your device with an updated antivirus and consider rotating private keys or using a new wallet for future transactions. Report the domain to your browser, wallet provider, and local cybercrime units. Always verify URLs against official project websites and avoid clicking ads or links from untrusted sources. Using hardware wallets and enabling transaction simulation features can further reduce risk in high-value interactions. ## EVIDENCE HASHES ---------------------------------------------------------------- TLS cert SHA-256: f07b48104247b3ed7a92a56cc038c9e5fb0a5284e902c2a17447f34bb6c74333 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (volunteer takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/balaancer-dex-us.pages.dev/ JSON API: https://api.destroy.tools/v1/check?domain=balaancer-dex-us.pages.dev Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: volunteer-driven open-source threat-intelligence platform. Tracked: 145,326 domains (56,089 alive under monitoring, 88,982 confirmed takedowns/dead). Site: https://phishdestroy.io