# presale99bitcoin.pages.dev — SUSPICIOUS > presale99bitcoin.pages.dev impersonates Bitcoin in a crypto drainer scam. Verify URLs via PhishDestroy before any crypto transactions. VirusTotal: 0/95. ## Summary PhishDestroy identifies presale99bitcoin.pages.dev as an active Bitcoin brand impersonation domain. This site poses a HIGH RISK to cryptocurrency users through targeted impersonation of Bitcoin, a globally recognized brand in digital assets. This domain was flagged by PhishDestroy’s domain intelligence pipeline using seed a96bfc. VirusTotal currently shows 0/95 security engines detecting this domain, indicating it remains under the radar of mainstream scanners as of the latest scan. The site operates behind Cloudflare, Inc. with a Google Trust Services SSL certificate, resolving to IP 188.114.96.3. While technical infrastructure appears legitimate (Cloudflare fronting, valid SSL), the content actively impersonates Bitcoin, a tactic commonly associated with cryptocurrency drainer scams designed to steal wallet credentials or initiate unauthorized transfers. Given the lack of detection and the domain’s active status, users should treat presale99bitcoin.pages.dev as HIGH RISK for crypto drainer operations. Bitcoin does not host “presale” events on third-party domains like pages.dev. Users are advised to avoid visiting or interacting with this domain. If exposed, immediately disconnect from the site, scan devices for malware, and revoke any wallet connection prompts. Verify legitimate Bitcoin communications only through official channels at bitcoin.org. PhishDestroy recommends cross-checking suspicious URLs using its real-time threat intelligence before engaging with any crypto-related website. ## Threat Details - Verdict: SUSPICIOUS - Site status: unknown (HTTP ?) - Target brand: Bitcoin ## Domain Intelligence - Registrar: Cloudflare, Inc. - IP: 188.114.96.3 ## Detection Status - VirusTotal: 0 vendors flagged - Google Safe Browsing: clean - Blocklists: 0 hits ## Evidence - Cloudflare Radar: https://radar.cloudflare.com/scan/0386547e-c8bb-4876-8e0b-16f31f78a3ad - PhishDestroy: https://phishdestroy.io/domain/presale99bitcoin.pages.dev/ - LLM endpoint: https://phishdestroy.io/domain/presale99bitcoin.pages.dev/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/presale99bitcoin.pages.dev/ Last updated: 2026-03-24