# rrrr-94c.pages.dev — SUSPICIOUS > PhishDestroy flags rrrr-94c.pages.dev as an active crypto-draining site with 0/95 VirusTotal detections. Blocked by ScamSniffer; rotate assets now. ## Summary PhishDestroy identifies rrrr-94c.pages.dev as an active crypto-draining portal masquerading as a legitimate wallet service. This site lures users into connecting their digital wallets and silently drains tokens via malicious smart-contract calls once authorization is granted. The domain resolves to IP 188.114.96.3 and uses a Google Trust Services SSL certificate to appear trustworthy, yet it currently evades antivirus detection with zero out of ninety-five VirusTotal engines flagging it. This domain was flagged by ScamSniffer and appears on one security blocklist. It is registered through Cloudflare, Inc., leveraging Cloudflare Pages for fast turn-up and evasion. Despite zero detections on VirusTotal as of the latest scan, behavior observed by threat analysts confirms ongoing drainer operations targeting Ethereum and Solana wallet holders. If you visited rrrr-94c.pages.dev, disconnect your wallet immediately using your wallet’s “Disconnect” or “Reject All” button. Revoke any unauthorized smart-contract approvals via reputable tools such as revoke.cash or Phantom’s built-in revoke feature. Rotate exposed private keys only after confirming no active sessions remain, and consider transferring remaining assets to a newly generated wallet. Monitor on-chain activity for suspicious transfers and report the domain to your security provider and relevant blockchain explorers. ## Threat Details - Verdict: SUSPICIOUS - Site status: unknown (HTTP ?) ## Domain Intelligence - Registrar: Cloudflare, Inc. - IP: 188.114.96.3 ## Detection Status - VirusTotal: 0 vendors flagged - Google Safe Browsing: clean - Blocklists: 1 hits Lists: ["ScamSniffer"] ## Evidence - Cloudflare Radar: https://radar.cloudflare.com/scan/7ee6e57d-5037-434a-bc08-2610c610d3de - PhishDestroy: https://phishdestroy.io/domain/rrrr-94c.pages.dev/ - LLM endpoint: https://phishdestroy.io/domain/rrrr-94c.pages.dev/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/rrrr-94c.pages.dev/ Last updated: 2026-03-22