# io-start-trzr-pages.pages.dev — SUSPICIOUS > io-start-trzr-pages.pages.dev is a crypto drainer phishing site with 2 out of 95 VirusTotal detections, impersonating legitimate services. ## Summary PhishDestroy identifies io-start-trzr-pages.pages.dev as an active crypto drainer phishing page designed to steal cryptocurrency by tricking visitors into connecting malicious wallets or entering seed phrases. This domain lures users with fake landing pages that mimic legitimate blockchain services, liquidity pools, or wallet interfaces, prompting wallet connections for fraudulent transactions. Once a user grants permissions or submits credentials, the attacker drains funds directly from connected wallets or harvests private keys for offline exploitation. This specific threat is part of a growing trend where phishing domains use legitimate-looking subdomains (pages.dev) and trustworthy SSL providers (Google Trust Services) to appear credible and bypass browser warnings. This domain was flagged by PhishDestroy with elevated risk status and was registered through Cloudflare, Inc., resolving to IP 188.114.96.3. VirusTotal analysis shows only 2 out of 95 security vendors currently detect this domain as malicious, highlighting how new or evasive phishing infrastructure often slips past automated defenses. The seeds.pages.dev subdomain structure is commonly exploited by threat actors to host phishing kits, and this page fits that pattern. While the SSL certificate comes from a reputable source (Google Trust Services), this does not guarantee site safety, as threat actors frequently weaponize trusted issuers to appear legitimate. If you visited io-start-trzr-pages.pages.dev, immediately disconnect your wallet if you connected it to the site. Do not enter any passwords, seed phrases, or private keys. Revoke any permissions granted to unknown or suspicious smart contracts or wallet connections through blockchain explorers like Etherscan or your wallet’s interface. Next, clear your browser cache and cookies related to the site, and consider running a malware scan on your device. Report the domain as malicious on PhishDestroy and share your experience on platforms like Reddit or crypto security forums to alert others. Always verify URLs through trusted sources or security tools before interacting with crypto-related links, as this domain continues to operate with minimal detection despite its intent to defraud. ## Threat Details - Verdict: SUSPICIOUS - Site status: unknown (HTTP ?) ## Domain Intelligence - Registrar: Cloudflare, Inc. - IP: 188.114.96.3 ## Detection Status - VirusTotal: 2 vendors flagged - Google Safe Browsing: clean - Blocklists: 0 hits ## Evidence - Cloudflare Radar: https://radar.cloudflare.com/scan/e033da40-3d23-4881-9013-55082dadd9ab - PhishDestroy: https://phishdestroy.io/domain/io-start-trzr-pages.pages.dev/ - LLM endpoint: https://phishdestroy.io/domain/io-start-trzr-pages.pages.dev/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/io-start-trzr-pages.pages.dev/ Last updated: 2026-03-21