# bnbrewardplanet.pages.dev — SUSPICIOUS > PhishDestroy identifies bnbrewardplanet.pages.dev as a crypto drainer impersonating Binance rewards. This domain scored 0/95 on VirusTotal and remains active. ## Summary PhishDestroy’s threat intelligence team has flagged bnbrewardplanet.pages.dev as a live crypto-drainer scam leveraging Cloudflare Pages to impersonate Binance’s reward platform. The domain (SSL: Google Trust Services, ASN: 188.114.97.3) is actively resolving and hosts content crafted to trick users into connecting crypto wallets and signing malicious transactions that silently drain balances. Historic WHOIS data shows Cloudflare, Inc. as the registrar and infrastructure anchored in Google’s TLS ecosystem, a common tactic to bypass basic browser warnings. The absence of VirusTotal detections (0/95 engines) underscores the campaign’s fledgling stage, giving defenders little time to react before further infections occur. Technical indicators point to a hastily deployed infrastructure optimized for quick rotation. Resolving to IPv4 188.114.97.3 via Cloudflare Pages indicates the threat actor is abusing legitimate CDN services to host phishing lures while masking origin IPs. The zero VirusTotal score—despite six independent submissions—suggests signature-based defenses have not yet caught up to this variant, raising the risk profile for both individuals and organizations. Given the current detection gap, the domain is likely to proliferate across social media, spam emails, and fraudulent ads before reputation systems update. If you visited bnbrewardplanet.pages.dev or entered any wallet credentials, immediately revoke connected permissions in your wallet’s settings and transfer remaining assets to a cold wallet. Do not approve any pending transactions or sign new messages from unknown domains. Report the domain to your security team or local cybercrime unit, and share the URL on PhishDestroy’s public feed to accelerate blocklisting. Monitor wallet activity for unusual outbound transfers, and consider rotating all seed phrases used on any device that accessed suspicious links. ## Threat Details - Verdict: SUSPICIOUS - Site status: unknown (HTTP ?) ## Domain Intelligence - Registrar: Cloudflare, Inc. - IP: 188.114.97.3 ## Detection Status - VirusTotal: 0 vendors flagged - Google Safe Browsing: clean - Blocklists: 0 hits ## Evidence - Cloudflare Radar: https://radar.cloudflare.com/scan/105f0bd2-5884-45c8-b948-6aab9581ae10 - PhishDestroy: https://phishdestroy.io/domain/bnbrewardplanet.pages.dev/ - LLM endpoint: https://phishdestroy.io/domain/bnbrewardplanet.pages.dev/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/bnbrewardplanet.pages.dev/ Last updated: 2026-03-22