# salomon-bvi.pages.dev — SUSPICIOUS > PhishDestroy identifies salomon-bvi.pages.dev as a crypto drainer impersonating Salomon. 2/95 vendors flagged this active domain resolving to 188.114.96.3. ## Summary PhishDestroy identifies salomon-bvi.pages.dev as a crypto drainer impersonating Salomon. This domain masquerades as the luxury footwear and apparel brand Salomon to deceive users into connecting cryptocurrency wallets under the guise of limited-edition product releases or exclusive drops. Upon interaction, the page likely initiates unauthorized wallet drainer scripts that exfiltrate digital assets without user consent, leveraging social engineering tactics tied to high-demand brand merchandise. Users who connect their wallets risk immediate financial loss as the drainer executes silent, malicious transactions to external addresses controlled by threat actors. This domain was flagged by PhishDestroy after analysis uncovered elevated risk indicators. VirusTotal analysis confirms 2 out of 95 security vendors detected malicious activity linked to salomon-bvi.pages.dev. The domain is registered through Cloudflare, Inc., a common choice among threat actors seeking anonymity and rapid provisioning of malicious infrastructure. The domain resolves to IP address 188.114.96.3, an address associated with known malicious hosting activity. The domain uses a valid SSL certificate issued by Google Trust Services, which enhances its credibility and increases the likelihood of successful deception. Given the active status and low detection rate, this domain poses a significant threat to cryptocurrency users seeking Salomon-branded products. Users who visited or interacted with salomon-bvi.pages.dev should immediately disconnect their cryptocurrency wallets and revoke any unauthorized connections through their wallet interface. Do not approve any pending transactions. Scan connected devices for malware using reputable antivirus tools. Report the domain to PhishDestroy and your wallet provider. Avoid any future visits to this domain. Remain vigilant for phishing attempts across similar brand impersonations and verify URLs through official Salomon channels before engaging with any digital storefronts. ## Threat Details - Verdict: SUSPICIOUS - Site status: unknown (HTTP ?) ## Domain Intelligence - Registrar: Cloudflare, Inc. - IP: 188.114.96.3 ## Detection Status - VirusTotal: 2 vendors flagged - Google Safe Browsing: clean - Blocklists: 0 hits ## Evidence - Cloudflare Radar: https://radar.cloudflare.com/scan/8e63f9c5-4f9e-4e5d-9a51-27b6b648ae66 - PhishDestroy: https://phishdestroy.io/domain/salomon-bvi.pages.dev/ - LLM endpoint: https://phishdestroy.io/domain/salomon-bvi.pages.dev/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/salomon-bvi.pages.dev/ Last updated: 2026-03-22