# dqwdq.pages.dev — SUSPICIOUS > dqwdq.pages.dev is a crypto drainer impersonating legitimate brands. Flagged by 3 of 95 VirusTotal vendors. Verify legitimacy on PhishDestroy before interacting. ## Summary PhishDestroy identifies dqwdq.pages.dev as an active crypto drainer posing as a trusted brand. This domain is currently operational and distributing malicious payloads to unsuspecting users. The site leverages deceptive tactics, including fake login portals and fraudulent transaction confirmations, to trick victims into authorizing unauthorized cryptocurrency transfers. Intelligence confirms this is a high-risk threat vector with real-world consequences, including drained wallets and stolen digital assets. This domain was flagged by 3 of 95 VirusTotal security vendors, registered through Cloudflare, Inc., and resolves to IP address 172.66.47.77. It appears on 1 known security blocklist and is blocked by ScamSniffer. The domain holds an SSL certificate issued by Google Trust Services, indicating use of encryption to appear legitimate. Despite its seemingly reputable infrastructure, this domain remains a malicious actor in the cryptocurrency ecosystem. Current status of dqwdq.pages.dev is active and evolving, with active distribution campaigns identified. PhishDestroy recommends immediate avoidance of this domain and any associated links or advertisements. Users who have engaged with this site should revoke any wallet approvals, transfer remaining assets to cold storage, and report the domain to PhishDestroy for further analysis. Always verify URLs through PhishDestroy’s real-time scanner before entering credentials or initiating transactions. ## Threat Details - Verdict: SUSPICIOUS - Site status: unknown (HTTP ?) ## Domain Intelligence - Registrar: Cloudflare, Inc. - IP: 172.66.47.77 ## Detection Status - VirusTotal: 3 vendors flagged - Google Safe Browsing: clean - Blocklists: 1 hits Lists: ["ScamSniffer"] ## Evidence - Cloudflare Radar: https://radar.cloudflare.com/scan/2eceb269-9b92-4c01-8640-e7e255d1794a - PhishDestroy: https://phishdestroy.io/domain/dqwdq.pages.dev/ - LLM endpoint: https://phishdestroy.io/domain/dqwdq.pages.dev/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/dqwdq.pages.dev/ Last updated: 2026-03-29