# bitcoindirectoryfolder.pages.dev — MALICIOUS > bitcoindirectoryfolder.pages.dev impersonates Bitcoin in a crypto-drainer scam, flagged by 7/95 VirusTotal vendors. Avoid this active credential theft site now. ## Summary PhishDestroy identifies bitcoindirectoryfolder.pages.dev as an active brand-impersonation scam targeting Bitcoin users. This fraudulent site mimics the official Bitcoin brand to trick visitors into connecting crypto wallets or entering sensitive credentials, which are then drained by malicious smart contracts. This domain was flagged by 7 of 95 VirusTotal security vendors within hours of going live. It was registered through Cloudflare on Google Trust Services infrastructure and resolves to IP 188.114.97.3, a Cloudflare anycast range often abused in crypto-drainer campaigns. If you visited bitcoindirectoryfolder.pages.dev, disconnect your wallet immediately, revoke any unauthorized permissions via your wallet’s settings, and run a malware scan on your device. Never enter seed phrases or private keys on any site claiming to be Bitcoin-related; always verify URLs against the official bitcoin.org list. ## Threat Details - Verdict: MALICIOUS - Site status: unknown (HTTP ?) - Target brand: Bitcoin ## Domain Intelligence - Registrar: Cloudflare, Inc. - IP: 188.114.97.3 ## Detection Status - VirusTotal: 7 vendors flagged - Google Safe Browsing: clean - Blocklists: 0 hits ## Evidence - Cloudflare Radar: https://radar.cloudflare.com/scan/9123417e-5332-48ab-8490-1343e6542c5e - PhishDestroy: https://phishdestroy.io/domain/bitcoindirectoryfolder.pages.dev/ - LLM endpoint: https://phishdestroy.io/domain/bitcoindirectoryfolder.pages.dev/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/bitcoindirectoryfolder.pages.dev/ Last updated: 2026-03-29