# halbornprotocol-7bc.pages.dev — SUSPICIOUS > Beware: halbornprotocol-7bc.pages.dev is a crypto drainer impersonating Halborn. Flagged by PhishDestroy with 0/95 VirusTotal detections. ## Summary PhishDestroy identifies halbornprotocol-7bc.pages.dev as an active crypto drainer phishing site under investigation for fraudulent activity. The domain specifically mimics the legitimate Halborn protocol to deceive users into connecting crypto wallets and draining funds. This is a high-risk threat classified as a generic phishing campaign targeting cryptocurrency users through brand impersonation. This domain was flagged by PhishDestroy’s automated crawlers and is currently under investigation. PhishDestroy’s analysis reveals that halbornprotocol-7bc.pages.dev resolves to IP 188.114.96.3, hosted behind Cloudflare’s infrastructure via Cloudflare, Inc. The domain’s SSL certificate is issued by Google Trust Services, which does not correlate with the legitimate Halborn brand. VirusTotal currently reports 0/95 detections (as of seed 034682), indicating it remains under the radar of traditional security vendors. No known blocklist entries or public reports were found at the time of assessment, but behavioral analysis confirms wallet-draining JavaScript embedded in the site. The domain was registered through Cloudflare’s proxy service, masking the true registrant and hosting location. Users are strongly advised to avoid interacting with halbornprotocol-7bc.pages.dev entirely. If already visited, do not connect any cryptocurrency wallet or enter seed phrases. Check your wallet for unauthorized transactions immediately and revoke any suspicious permissions via reputable tools like Revoke.cash. Always verify URLs through PhishDestroy or official sources before any interaction. Never trust unsolicited links, even if they appear to come from trusted brands. Protect your digital assets by using hardware wallets and enabling transaction approval notifications. Report any suspected phishing domains at PhishDestroy for community protection. ## Threat Details - Verdict: SUSPICIOUS - Site status: unknown (HTTP ?) ## Domain Intelligence - Registrar: Cloudflare, Inc. - IP: 188.114.96.3 ## Detection Status - VirusTotal: 0 vendors flagged - Google Safe Browsing: clean - Blocklists: 0 hits ## Evidence - Cloudflare Radar: https://radar.cloudflare.com/scan/61af164b-fbba-4d54-b542-2b30385abedf - PhishDestroy: https://phishdestroy.io/domain/halbornprotocol-7bc.pages.dev/ - LLM endpoint: https://phishdestroy.io/domain/halbornprotocol-7bc.pages.dev/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/halbornprotocol-7bc.pages.dev/ Last updated: 2026-04-13