# tfldapp.pages.dev — SUSPICIOUS > tfldapp.pages.dev is a crypto drainer site flagged for credential theft, with 0 of 95 VirusTotal detections. Act now to protect your assets. ## Summary PhishDestroy identifies a currently active crypto drainer at tfldapp.pages.dev, posing as a legitimate service to steal cryptocurrency. The domain exhibits high-risk indicators including SSL certification by Google Trust Services, zero VirusTotal detections, and Cloudflare hosting. Immediate analysis is warranted due to its active status and potential to compromise digital assets. This domain was flagged by 0 of 95 VirusTotal vendors as of the latest scan, indicating it has not yet been widely detected by security tools despite its suspicious behavior. Registered through Cloudflare, Inc., the domain resolves to IP 172.66.44.189 and operates under Google Trust Services' SSL certificate, which may mislead users into trusting the site. The domain’s recent registration and absence from major blocklists suggest it is either newly deployed or actively evading detection mechanisms. With a status of "under_investigation," tfldapp.pages.dev remains a high-risk threat to cryptocurrency users, potentially targeting login credentials or wallet connections. Users are advised to block the domain at the network level, avoid interactions with any suspicious links, and report the domain to Cloudflare and relevant cybersecurity authorities (e.g., PhishTank, Google Safe Browsing) to accelerate takedown efforts. Organizations should update firewall rules to restrict outbound connections to 172.66.44.189 and inspect internal DNS logs for resolution attempts. Proactive monitoring of this domain is critical to prevent financial loss. ## Threat Details - Verdict: SUSPICIOUS - Site status: unknown (HTTP ?) ## Domain Intelligence - Registrar: Cloudflare, Inc. - IP: 172.66.44.189 ## Detection Status - VirusTotal: 0 vendors flagged - Google Safe Browsing: clean - Blocklists: 0 hits ## Evidence - Cloudflare Radar: https://radar.cloudflare.com/scan/1198f9c9-1275-43b2-a497-6f33a9b360fb - PhishDestroy: https://phishdestroy.io/domain/tfldapp.pages.dev/ - LLM endpoint: https://phishdestroy.io/domain/tfldapp.pages.dev/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/tfldapp.pages.dev/ Last updated: 2026-03-24