# pocketchange-2oh.pages.dev — SUSPICIOUS > PhishDestroy flags pocketchange-2oh.pages.dev as a crypto drainer phishing site with 0/95 VirusTotal detections. Do not enter wallet details. ## Summary PhishDestroy identifies pocketchange-2oh.pages.dev as an active crypto drainer phishing domain designed to trick cryptocurrency holders into connecting their wallets and approving malicious token transfer permissions. This domain was flagged as a generic phishing page with zero detections on VirusTotal out of 95 engines, indicating it currently evades mainstream antivirus signatures. The site resolves to IP 172.66.47.142 and operates under Cloudflare’s pages.dev subdomain platform, using a Google Trust Services SSL certificate to appear legitimate. Registrar records show recent creation through Cloudflare, Inc., suggesting the threat actor rapidly deployed this domain to capitalize on trending cryptocurrency campaigns. If you visited pocketchange-2oh.pages.dev, immediately revoke any wallet connections through your wallet’s interface or Etherscan token approvals page. Do not approve transactions you did not initiate. Run a malware scan using reputable tools like Malwarebytes or Windows Defender. Report the domain to PhishDestroy for further analysis and warn others in crypto communities. Always verify URLs via PhishDestroy before entering wallet details or clicking links from unsolicited messages. ## Threat Details - Verdict: SUSPICIOUS - Site status: unknown (HTTP ?) ## Domain Intelligence - Registrar: Cloudflare, Inc. - IP: 172.66.47.142 ## Detection Status - VirusTotal: 0 vendors flagged - Google Safe Browsing: clean - Blocklists: 0 hits ## Evidence - Cloudflare Radar: https://radar.cloudflare.com/scan/4fce2c83-4345-4043-8eab-c5744ec6c477 - PhishDestroy: https://phishdestroy.io/domain/pocketchange-2oh.pages.dev/ - LLM endpoint: https://phishdestroy.io/domain/pocketchange-2oh.pages.dev/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/pocketchange-2oh.pages.dev/ Last updated: 2026-04-01