# greenbitcoin-claiim.pages.dev — SUSPICIOUS > PhishDestroy identifies greenbitcoin-claiim.pages.dev as a crypto drainer impersonating Bitcoin (1/95 vendors flagged). Verify this domain before interacting. ## Summary PhishDestroy identifies greenbitcoin-claiim.pages.dev as an active crypto drainer impersonating Bitcoin to steal digital assets. This fraudulent site resolves to IP 188.114.97.3 and holds an SSL certificate issued by Google Trust Services, attempting to appear legitimate. The domain was flagged by 1 out of 95 security vendors on VirusTotal and already appears on 2 security blocklists including Enkrypt and ScamSniffer, indicating widespread recognition as a threat. This domain was registered through Cloudflare, Inc., leveraging the service’s infrastructure to obscure its true origins while targeting unsuspecting users interested in Bitcoin. The specific threat involves crypto drainer functionality, where visitors’ wallet connections are compromised to silently transfer funds without consent. The combination of low detection on VirusTotal (1/95) and immediate blocking by multiple browser extensions highlights the deceptive nature of this site, which is designed to mimic legitimate Bitcoin-related services. If you have visited greenbitcoin-claiim.pages.dev, immediately disconnect your wallet, revoke any connected permissions, and transfer remaining assets to a secure wallet. Scan your system for malware and change passwords linked to crypto accounts. Verify all links and domains using PhishDestroy before entering any credentials or connecting wallets to prevent irreversible financial loss. ## Threat Details - Verdict: SUSPICIOUS - Site status: unknown (HTTP ?) - Target brand: Bitcoin ## Domain Intelligence - Registrar: Cloudflare, Inc. - IP: 188.114.97.3 ## Detection Status - VirusTotal: 1 vendors flagged - Google Safe Browsing: clean - Blocklists: 2 hits Lists: ["Enkrypt", "ScamSniffer"] ## Evidence - Cloudflare Radar: https://radar.cloudflare.com/scan/bf1337d7-6583-4cc3-8e8d-c066019af7dd - PhishDestroy: https://phishdestroy.io/domain/greenbitcoin-claiim.pages.dev/ - LLM endpoint: https://phishdestroy.io/domain/greenbitcoin-claiim.pages.dev/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/greenbitcoin-claiim.pages.dev/ Last updated: 2026-03-24