# ton-2mj.pages.dev — SUSPICIOUS > ton-2mj.pages.dev is hosting a fake cryptocurrency giveaway scam. VirusTotal shows 0/95 detections. Check the full report. ## Summary PhishDestroy identifies ton-2mj.pages.dev as a live phishing domain impersonating a cryptocurrency giveaway to siphon user funds. The page leverages a spoofed 'TON Foundation' branding to trick visitors into connecting wallets and approving malicious token transfers. No known drainer kit signatures match this campaign yet, but the generic landing page structure suggests reuse of commoditized phishing templates targeting TON and ETH ecosystems. The domain resolves to Cloudflare-registered infrastructure, indicating evasion tactics designed to obscure origin and prolong uptime. Technical indicators confirm low detection fidelity at present: VirusTotal score stands at 0/95, with no antivirus or URL scanner flagging the payload. The domain routes through IP 172.66.47.162 and uses a Google Trust Services SSL certificate to simulate legitimacy. Registered via Cloudflare, Inc., it benefits from fast-flux DNS rotation and edge caching, complicating takedown efforts. While creation date remains undisclosed in public records, the infrastructure’s evasive configuration suggests recent deployment targeting high-traffic crypto communities. Current status is active and under investigation, with no immediate blocklist inclusion. Response actions include coordination with Cloudflare Trust & Safety for domain takedown and SSL certificate revocation. Despite low AV coverage, behavioral monitoring flags the domain due to rapid domain generation and suspicious redirect chains. Remaining risk is assessed as elevated given the absence of proactive blocking and the domain’s utilization of trusted hosting providers. Users are advised to avoid interacting with any TON-related giveaway links and to verify official channels before engaging with cryptocurrency transactions. ## Threat Details - Verdict: SUSPICIOUS - Site status: unknown (HTTP ?) ## Domain Intelligence - Registrar: Cloudflare, Inc. - IP: 172.66.47.162 ## Detection Status - VirusTotal: 0 vendors flagged - Google Safe Browsing: clean - Blocklists: 0 hits ## Evidence - Cloudflare Radar: https://radar.cloudflare.com/scan/294e0173-bec3-4650-af2b-a7e2c3decf1a - PhishDestroy: https://phishdestroy.io/domain/ton-2mj.pages.dev/ - LLM endpoint: https://phishdestroy.io/domain/ton-2mj.pages.dev/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/ton-2mj.pages.dev/ Last updated: 2026-03-22