# earn-lavanet.pages.dev — SUSPICIOUS > earn-lavanet.pages.dev hosts a crypto drainer posing as a phishing site. Detected by just 2/95 VirusTotal vendors, yet flagged by ScamSniffer and Enkrypt. ## Summary The domain earn-lavanet.pages.dev has been identified as an active crypto drainer, a specialized form of phishing designed to illicitly transfer cryptocurrency assets from unsuspecting victims. This threat is classified as elevated due to its targeting of digital asset holders and the deceptive tactics employed to trick users into connecting their wallets or entering credentials. Unlike generic phishing attempts, crypto drainers actively exploit blockchain transaction mechanics to siphon funds in real-time, making them particularly dangerous in the Web3 ecosystem. This domain was flagged by multiple security vendors, including Enkrypt and ScamSniffer, with additional confirmations from 2 out of 95 VirusTotal analyzers. The infrastructure behind the domain resolves to IP address 172.66.47.113, which is hosted via Cloudflare, Inc. The domain leverages a Google Trust Services SSL certificate, potentially adding a veneer of legitimacy. Notably, it has been cataloged on two separate blocklists, indicating prior detections of malicious behavior. These attributes collectively underscore the domain's malicious intent and operational sophistication. Organizations and individuals should immediately block this domain at the network perimeter and instruct users to avoid interactions with any associated URLs or subdomains. Users who may have engaged with earn-lavanet.pages.dev should review their wallet transactions for unauthorized transfers and revoke any connected permissions through blockchain explorers or wallet interfaces. Implementing browser extensions or security tools that detect crypto drainer signatures can provide an additional layer of defense. Regularly monitoring threat intelligence feeds for emerging indicators will help preempt future exposure to similar threats. ## Threat Details - Verdict: SUSPICIOUS - Site status: unknown (HTTP ?) ## Domain Intelligence - Registrar: Cloudflare, Inc. - IP: 172.66.47.113 ## Detection Status - VirusTotal: 2 vendors flagged - Google Safe Browsing: clean - Blocklists: 2 hits Lists: ["Enkrypt", "ScamSniffer"] ## Evidence - Cloudflare Radar: https://radar.cloudflare.com/scan/8e6c7f78-4226-48ca-ad5a-c6398091413d - PhishDestroy: https://phishdestroy.io/domain/earn-lavanet.pages.dev/ - LLM endpoint: https://phishdestroy.io/domain/earn-lavanet.pages.dev/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/earn-lavanet.pages.dev/ Last updated: 2026-03-26