# tersre-oi-suiite.pages.dev — SUSPICIOUS > tersre-oi-suiite.pages.dev hosts a crypto drainer posing as a login page. VirusTotal flags it 2/95. Verify domains on PhishDestroy for safety. ## Summary PhishDestroy identifies the active domain tersre-oi-suiite.pages.dev as an elevated-risk crypto drainer impersonating a generic login interface. This PageCloud-hosted site leverages Cloudflare infrastructure and a Google Trust Services SSL certificate to appear legitimate, while its primary function is to intercept and exfiltrate cryptocurrency wallet credentials and private keys. This domain was flagged with a low detection rate of 2 out of 95 VirusTotal security vendors, operates under the Cloudflare, Inc. registrar, and resolves to IP address 188.114.97.3. Its association with PageCloud (via *.pages.dev) and the use of a publicly trusted certificate demonstrate the sophistication of the threat actor in evading browser-based security controls. The low blocklist prevalence suggests this campaign is either newly launched or carefully targeted to avoid widespread detection. Users who have accessed tersre-oi-suiite.pages.dev should immediately disconnect any active wallet connections, revoke unauthorized permissions through their wallet’s interface, and transfer remaining assets to a clean wallet. Scan all connected devices for malware or rogue browser extensions using reputable security software. Report the domain to PhishDestroy and monitor transaction logs for suspicious activity. Do not re-enter credentials or sign transactions from this domain—assume compromise and treat all related assets as potentially lost. ## Threat Details - Verdict: SUSPICIOUS - Site status: unknown (HTTP ?) ## Domain Intelligence - Registrar: Cloudflare, Inc. - IP: 188.114.97.3 ## Detection Status - VirusTotal: 2 vendors flagged - Google Safe Browsing: clean - Blocklists: 0 hits ## Evidence - Cloudflare Radar: https://radar.cloudflare.com/scan/6d1ffe51-2a8b-427a-bbfa-d45e6e6d36b0 - PhishDestroy: https://phishdestroy.io/domain/tersre-oi-suiite.pages.dev/ - LLM endpoint: https://phishdestroy.io/domain/tersre-oi-suiite.pages.dev/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/tersre-oi-suiite.pages.dev/ Last updated: 2026-03-22