# PhishDestroy threat dossier — guide-balancer-defii.pages.dev ================================================================ Fetched: 2026-04-25 16:27:05 UTC Canonical: https://phishdestroy.io/domain/guide-balancer-defii.pages.dev/ ## VERDICT ---------------------------------------------------------------- CRITICAL THREAT — DO NOT VISIT Composite threat score: 96/100 (PhishDestroy scoring — see methodology below) Scam classification: Impersonation Targeted brand: Balancer ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 1/94 security vendors flagged this domain Flagging vendors: LevelBlue ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 188.114.96.3 (CA, Toronto) ASN: AS13335 Cloudflare, Inc. Hosting org: CloudFlare, Inc. Registrar: Cloudflare, Inc. Nameservers: decker.ns.cloudflare.com, rachel.ns.cloudflare.com Registered: 2026-04-09 Page title: Balancer DeFi – Smart Liquidity for Decentralized Finance HTTP response: 200 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Google Trust Services / WE1 Expires: 2026-07-08 Status: INVALID chain Fingerprint: a9c06a092051bd3251a2ab41d338bd6eaace0c5a748d98357590956f7e7fae29 ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-04-09 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-04-09 14:22:38 UTC (by PhishDestroy tracker) Last verified: 2026-04-21 16:07:20 UTC Current status: ACTIVE / observable ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019d71f9-d28d-726e-af9b-ec1dee8cbfcc/ Wayback Machine: https://web.archive.org/web/*/guide-balancer-defii.pages.dev crt.sh CT logs: https://crt.sh/?q=%25.guide-balancer-defii.pages.dev Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=guide-balancer-defii.pages.dev AlienVault OTX: https://otx.alienvault.com/indicator/domain/guide-balancer-defii.pages.dev URLhaus: https://urlhaus.abuse.ch/host/guide-balancer-defii.pages.dev/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-04-09 14:23:38 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] PhishDestroy identifies guide-balancer-defii.pages.dev as an active brand impersonation domain targeting Balancer users. The site mimics Balancer’s branding to deceive visitors into connecting wallets or revealing credentials, a classic tactic in crypto drainer campaigns. The risk level remains under investigation, but the domain’s deliberate mimicry of a recognized DeFi protocol qualifies it as a high-priority threat to financial safety. Technical analysis confirms the domain resolves to IP 188.114.96.3 and operates under Cloudflare’s infrastructure, which is frequently abused for hosting malicious content due to its anonymity features. The SSL certificate issued by Google Trust Services may lend false legitimacy, but it does not validate the site’s authenticity. At present, VirusTotal reports 0 detections across 95 engines, indicating this domain is actively evading detection despite clear malicious intent. This domain was flagged due to its direct impersonation of Balancer, a prominent automated market maker in decentralized finance. Cloudflare’s role as registrar and hosting provider complicates takedown efforts, as the service often delays or refuses to act on abuse reports without clear evidence of illegal activity. The domain’s infrastructure shares hosting with other suspicious services, suggesting a coordinated campaign rather than an isolated incident. While no confirmed blocklists have been updated to include this domain yet, its SSL certificate from a trusted authority and lack of detections make it particularly dangerous—users may unknowingly trust the site, believing it to be safe. The absence of detections should not be interpreted as safety; rather, it highlights the sophistication of modern impersonation tactics, where threat actors leverage reputable services to bypass security measures. To mitigate risk, users should immediately block guide-balancer-defii.pages.dev at the network and browser levels. Avoid accessing the domain under any circumstances, as even viewing the page could trigger malicious scripts or social engineering prompts. If you have interacted with this site—especially by connecting a wallet or entering credentials—revoke any connected permissions via your wallet’s approval manager and transfer remaining assets to a secure, isolated wallet. Report the domain to Balancer’s official security channels and to Cloudflare’s abuse team with evidence of impersonation. Enable enhanced browser protections such as uBlock Origin with anti-phishing filters and consider using hardware wallets for DeFi interactions to limit exposure. Monitor wallet transactions closely for unauthorized transfers. Proactive sharing of threat intelligence among crypto communities can help identify similar domains before they cause harm. ## EVIDENCE HASHES ---------------------------------------------------------------- TLS cert SHA-256: a9c06a092051bd3251a2ab41d338bd6eaace0c5a748d98357590956f7e7fae29 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (volunteer takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/guide-balancer-defii.pages.dev/ JSON API: https://api.destroy.tools/v1/check?domain=guide-balancer-defii.pages.dev Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: volunteer-driven open-source threat-intelligence platform. Tracked: 131,000+ phishing domains. Confirmed takedowns: 91,000+. Site: https://phishdestroy.io