# burnyourasa.pages.dev — SUSPICIOUS > burnyourasa.pages.dev hosts a crypto drainer posing as a wallet drainer tool with 0/95 VirusTotal detections. ## Summary PhishDestroy identifies burnyourasa.pages.dev as an active crypto drainer operation designed to trick users into connecting malicious wallet addresses. The domain impersonates legitimate crypto services by using a Pages.dev subdomain, a tactic commonly leveraged to bypass initial domain scrutiny. No explicit brand impersonation or drainer kit signature was observed in initial scans, but behavioral patterns align with known crypto-draining tools that monitor clipboard activity and wallet connections for theft. Users interacting with this site should assume their assets are at immediate risk. This domain resolves to IP 188.114.96.3 and is registered through Cloudflare, Inc. It holds a valid SSL certificate issued by Google Trust Services, which is frequently abused by malicious actors to lend false legitimacy. As of the latest scan, VirusTotal reports 0 detections out of 95 engines, indicating this threat is currently under the radar. The registration via Cloudflare may delay or obscure takedown efforts, and the relatively new age of the domain suggests opportunistic deployment. As of now, burnyourasa.pages.dev remains active and unblocked by major services like Google Safe Browsing. The absence of detections on VirusTotal and no public blocklist entries indicate this domain is still in early operational stages. Users are advised not to interact with any download prompts or wallet connection requests from this domain. Site owners and security teams should consider blocking 188.114.96.3 and using threat intelligence feeds that monitor crypto drainer toolkits. Remaining risk is moderate due to low detection coverage and Cloudflare’s protective infrastructure for the attacker. Immediate reporting to hosting providers and threat-sharing platforms is recommended to accelerate mitigation. ## Threat Details - Verdict: SUSPICIOUS - Site status: unknown (HTTP ?) ## Domain Intelligence - Registrar: Cloudflare, Inc. - IP: 188.114.96.3 ## Detection Status - VirusTotal: 0 vendors flagged - Google Safe Browsing: clean - Blocklists: 0 hits ## Evidence - Cloudflare Radar: https://radar.cloudflare.com/scan/2aac7168-9df3-44d7-8dc9-30fab52bdd04 - PhishDestroy: https://phishdestroy.io/domain/burnyourasa.pages.dev/ - LLM endpoint: https://phishdestroy.io/domain/burnyourasa.pages.dev/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/burnyourasa.pages.dev/ Last updated: 2026-03-24