# perpolator.lat — SUSPICIOUS > PhishDestroy identifies perpolator.lat as a live crypto drainer kit landing page hosted on a Let’s Encrypt site. The domain resolves to 188.114.96. ## Summary PhishDestroy initiated an active investigation into perpolator.lat on 2025-10-08 after confirming it is a generic phishing domain serving a cryptocurrency drainer kit. No explicit brand impersonation was detected at seed 5a41ff, indicating a commodity toolkit reused across multiple targets. The domain name suggests a spoofed “perpetual swap” trading portal, a common lure for users seeking leveraged crypto exposure. This domain was registered on 2026-03-23 through NICENIC INTERNATIONAL GROUP CO., LIMITED and is presently hosted on IP 188.114.96.3 secured via a Let’s Encrypt SSL certificate. VirusTotal currently reports a 0/95 detection score and the domain has not yet been flagged by Google Safe Browsing or any public blocklist according to available telemetry at the time of writing. The threat level remains under_investigation while additional sandbox detonation and YARA correlation are performed. Users should block perpolator.lat at DNS and firewall layers until the investigation concludes. Remaining risk is assessed as HIGH given the domain’s recent creation, active hosting, and commodity drainer payload which can exfiltrate wallet credentials and tokens within seconds of interaction. ## Threat Details - Verdict: SUSPICIOUS - Site status: unknown (HTTP ?) ## Domain Intelligence - Registered: 2026-03-23 09:00:17 - Registrar: NICENIC INTERNATIONAL GROUP CO., LIMITED - IP: 188.114.96.3 ## Detection Status - VirusTotal: 0 vendors flagged - Google Safe Browsing: clean - Blocklists: 0 hits ## Evidence - Cloudflare Radar: https://radar.cloudflare.com/scan/796eada0-3a20-4f14-bbfe-837c2db904b0 - PhishDestroy: https://phishdestroy.io/domain/perpolator.lat/ - LLM endpoint: https://phishdestroy.io/domain/perpolator.lat/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/perpolator.lat/ Last updated: 2026-03-23