# citrea.network — SUSPICIOUS > Explore the risks tied to citrea.network. Learn why this domain is under phishing investigation and how to protect yourself from potential scams. ## Summary PhishDestroy identifies citrea.network as an active domain under investigation for generic phishing activity. While no direct detections have been flagged by security vendors, the domain's behavior and context raise concerns about its potential use in deceptive schemes aimed at stealing sensitive user data. Such threats matter because phishing attacks can lead to financial loss, identity theft, and compromised personal information. Currently, citrea.network resolves to the IP address 172.67.168.209. Despite thorough scanning, VirusTotal reports zero detections among 95 security vendors, indicating the domain may be newly registered or employing evasion tactics. This lack of immediate detection necessitates closer monitoring and further analysis to determine if the domain is part of a larger phishing infrastructure or a transient malicious setup. Users are advised to exercise caution when interacting with unknown or suspicious domains like citrea.network. Avoid clicking unsolicited links or providing personal credentials without verification. Employ updated security tools and consider domain reputation checks before engaging. Staying vigilant helps mitigate risks while PhishDestroy continues to track and analyze this domain's activities. ## Threat Details - Verdict: SUSPICIOUS - Site status: dead (HTTP 403) - Page title: Suspected phishing site | Cloudflare ## Domain Intelligence - Registered: 2026-03-08 13:07:01 - Registrar: NiceNIC International Group Co., Limited - Country: HK - IP: 172.67.168.209 - IP Country: US - IP City: San Francisco - IP Org: AS13335 Cloudflare, Inc. - Nameservers: ["dawn.ns.cloudflare.com", "titan.ns.cloudflare.com"] - SSL Issuer: none ## Detection Status - VirusTotal: 3 vendors flagged Vendors: ["ADMINUSLabs", "Fortinet", "SOCRadar"] - Google Safe Browsing: clean - Blocklists: 3 hits Lists: ["PhishDestroy", "MetaMask", "SEAL"] ## Evidence - Screenshot: https://urlscan.io/screenshots/019ccd49-903b-74b9-b639-ea66aa3e0718.png - Cloudflare Radar: https://radar.cloudflare.com/scan/51593cb0-99a6-4168-b611-4dd5c265062a - Wayback Machine: https://web.archive.org/web/https://citrea.network - PhishDestroy: https://phishdestroy.io/domain/citrea.network/ - LLM endpoint: https://phishdestroy.io/domain/citrea.network/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/citrea.network/ Last updated: 2026-03-19