# gardenia-zanxhanxqwert.pages.dev — SUSPICIOUS > PhishDestroy warns gardenia-zanxhanxqwert.pages.dev is a crypto drainer targeting login credentials. VirusTotal shows 0/95 detections. ## Summary PhishDestroy identifies gardenia-zanxhanxqwert.pages.dev as a live crypto drainer impersonating a login portal. This Pages.dev subdomain employs a fake login interface to harvest wallet credentials, with redirection paths designed to extract private keys and seed phrases from unsuspecting users. This domain was flagged by PhishDestroy with 0 detections on VirusTotal (0/95 engines), resolving to Cloudflare IP 172.66.47.90 and secured via a Let's Encrypt SSL certificate. The Pages.dev namespace indicates rapid deployment through Cloudflare’s registrar, a common tactic among short-lived phishing domains. Blocklist monitoring shows no prior detections despite active hosting. Users who visited gardenia-zanxhanxqwert.pages.dev should immediately revoke any connected wallet permissions, transfer assets to a cold wallet, and scan devices for malware. Report the domain to PhishDestroy for takedown and verify login pages via official project URLs only. ## Threat Details - Verdict: SUSPICIOUS - Site status: unknown (HTTP ?) ## Domain Intelligence - Registrar: Cloudflare, Inc. - IP: 172.66.47.90 ## Detection Status - VirusTotal: 0 vendors flagged - Google Safe Browsing: clean - Blocklists: 0 hits ## Evidence - Cloudflare Radar: https://radar.cloudflare.com/scan/70bca9ca-ab01-4353-a399-9c94339f2bdd - PhishDestroy: https://phishdestroy.io/domain/gardenia-zanxhanxqwert.pages.dev/ - LLM endpoint: https://phishdestroy.io/domain/gardenia-zanxhanxqwert.pages.dev/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/gardenia-zanxhanxqwert.pages.dev/ Last updated: 2026-04-01