# dapwebbsyn.pages.dev — MALICIOUS > dapwebbsyn.pages.dev active crypto drainer impersonating MetaMask; 15/95 VirusTotal detections. Avoid this site immediately. ## Summary PhishDestroy identifies dapwebbsyn.pages.dev as an active crypto drainer impersonating MetaMask, posing severe risk to cryptocurrency users. This domain employs a classic phishing tactic by mimicking the legitimate MetaMask interface to trick visitors into connecting their wallets and unwittingly authorizing fraudulent transactions. Once connected, the drainer silently drains token balances, NFTs, and other digital assets. Victims often realize the theft only after funds vanish from their wallets, leaving little recourse for recovery. This campaign specifically targets users seeking Web3 connectivity or wallet management tools, exploiting their trust in recognized names within the ecosystem. This domain was flagged by 15 of 95 VirusTotal security vendors and has been added to multiple blocklists including MetaMask and SEAL. It was registered through Cloudflare, Inc., with the SSL certificate issued by Google Trust Services, giving it a false appearance of legitimacy. The domain resolved to IP 172.66.47.72 and was created to serve as a social engineering front, as confirmed by Google Safe Browsing’s SOCIAL_ENGINEERING classification. The combination of a free Pages.dev subdomain and HTTPS configuration suggests an attempt to bypass traditional security measures that rely on domain reputation or lack of encryption. If you visited dapwebbsyn.pages.dev, immediately disconnect your wallet from any dApps or Web3 interfaces it may have accessed. Revoke any wallet permissions it might have obtained—use tools like revoke.cash or wallet’s built-in permission manager. Transfer any remaining funds to a new, secure wallet using a different seed phrase. Scan your device for malware using reputable antivirus software, as this site may have installed keyloggers or trojans. Finally, report the domain and any suspicious transactions to MetaMask support and relevant blockchain security platforms to help block future attacks using this infrastructure. ## Threat Details - Verdict: MALICIOUS - Site status: unknown (HTTP ?) ## Domain Intelligence - Registrar: Cloudflare, Inc. - IP: 172.66.47.72 ## Detection Status - VirusTotal: 15 vendors flagged - Google Safe Browsing: FLAGGED - Blocklists: 2 hits Lists: ["MetaMask", "SEAL"] ## Evidence - Cloudflare Radar: https://radar.cloudflare.com/scan/50cdae5f-51b8-439a-8241-f8ec6349d178 - PhishDestroy: https://phishdestroy.io/domain/dapwebbsyn.pages.dev/ - LLM endpoint: https://phishdestroy.io/domain/dapwebbsyn.pages.dev/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/dapwebbsyn.pages.dev/ Last updated: 2026-03-26