# PhishDestroy threat dossier — comprpcv2.pages.dev ================================================================ Fetched: 2026-04-26 02:52:25 UTC Canonical: https://phishdestroy.io/domain/comprpcv2.pages.dev/ ## VERDICT ---------------------------------------------------------------- CRITICAL THREAT — DO NOT VISIT Composite threat score: 100/100 (PhishDestroy scoring — see methodology below) Scam classification: Impersonation Targeted brand: Compound ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 2/94 security vendors flagged this domain Flagging vendors: ADMINUSLabs, Kaspersky ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 172.66.47.180 (CA, Toronto) ASN: AS13335 Cloudflare, Inc. Hosting org: Cloudflare, Inc. Registrar: Cloudflare, Inc. Nameservers: giancarlo.ns.cloudflare.com, natasha.ns.cloudflare.com Registered: 2026-04-19 Page title: Compound | Dashboard HTTP response: 200 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Google Trust Services / WE1 Expires: 2026-07-11 Status: INVALID chain Fingerprint: a070873644116eab4938463de411c63185103b03d7c788658feaaa503c7fd3a9 ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-04-19 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-04-19 18:48:22 UTC (by PhishDestroy tracker) Last verified: 2026-04-21 19:40:04 UTC Current status: ACTIVE / observable ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019da66c-ecde-763f-970f-ba89d2461fbd/ Wayback Machine: https://web.archive.org/web/*/comprpcv2.pages.dev crt.sh CT logs: https://crt.sh/?q=%25.comprpcv2.pages.dev Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=comprpcv2.pages.dev AlienVault OTX: https://otx.alienvault.com/indicator/domain/comprpcv2.pages.dev URLhaus: https://urlhaus.abuse.ch/host/comprpcv2.pages.dev/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-04-19 18:49:31 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] comprpcv2.pages.dev is an active cryptocurrency drainer phishing domain currently under investigation for fraudulent activities. The domain masquerades as a legitimate service, likely impersonating a well-known brand to deceive users into connecting their wallets or entering sensitive credentials. Security researchers have flagged this domain as a high-risk threat due to its active deployment in phishing campaigns targeting cryptocurrency users. The platform hosting this domain, Cloudflare Pages, has not yet taken down the page, allowing the threat to persist. This domain was flagged by 0 of 95 VirusTotal vendors, indicating it has evaded detection by mainstream security tools. Registered through Cloudflare, Inc., the domain resolves to IP 172.66.47.180 and utilizes a Google Trust Services SSL certificate, which may lend false credibility to unsuspecting users. The infrastructure behind this domain suggests an attempt to exploit legitimate cloud services to host malicious content while leveraging trusted certificate authorities to appear legitimate. Despite its current low detection rate, the combination of active hosting and suspicious behavior warrants immediate caution. Users are strongly advised to avoid interacting with comprpcv2.pages.dev until further analysis is completed. PhishDestroy recommends verifying the safety of this domain using their comprehensive threat intelligence database. If you have recently visited this domain, disconnect your wallet immediately, revoke any unauthorized connections, and scan your devices for malware. Stay vigilant and report any suspicious activity to PhishDestroy to help protect the broader community from emerging threats. Always cross-check URLs and use trusted security tools before entering sensitive information. [Updates since narrative was generated:] - VirusTotal detections: now 2/94 (narrative was written when count was lower) ## EVIDENCE HASHES ---------------------------------------------------------------- Favicon MD5: 4af50c96ded8d36316fb8289b612dcec TLS cert SHA-256: a070873644116eab4938463de411c63185103b03d7c788658feaaa503c7fd3a9 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (volunteer takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/comprpcv2.pages.dev/ JSON API: https://api.destroy.tools/v1/check?domain=comprpcv2.pages.dev Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: volunteer-driven open-source threat-intelligence platform. Tracked: 131,000+ phishing domains. Confirmed takedowns: 91,000+. Site: https://phishdestroy.io