# tronqcan.pages.dev — SUSPICIOUS > PhishDestroy flags tronqcan.pages.dev as a crypto drainer phishing site. VirusTotal reports 0/95 detections, so verify it now on PhishDestroy before interacting. ## Summary PhishDestroy identifies tronqcan.pages.dev as a probable crypto drainer scam posing as a legitimate service. This malicious domain leverages Cloudflare’s Workers platform to host deceptive pages that trick users into connecting crypto wallets or entering seed phrases. Once a victim interacts with the site, the drainer silently siphons tokens or NFTs from connected wallets by exploiting permission approvals or fake transaction prompts. Users may not realize they’ve been compromised until assets vanish from their wallets, as drainers often operate without immediate detection, especially when hosted on reputable services like Cloudflare Workers. This domain was flagged through PhishDestroy’s automated pipeline, which detected crypto drainer behavior patterns. VirusTotal currently shows 0/95 security engines detecting the threat, indicating it remains under the radar despite active abuse. The domain resolves to IP 172.66.47.79 via Cloudflare, Inc., a common tactic to obscure hosting infrastructure. While the SSL certificate from Let’s Encrypt provides a veneer of legitimacy, it cannot validate the site’s intent. Blocklists and threat intelligence feeds may not yet include this domain due to its recent activation and low detection rate. If you visited tronqcan.pages.dev, disconnect your crypto wallet immediately and revoke any suspicious permissions via your wallet’s app or a reputable revoke tool like revoke.cash. Do not interact further with the site, as additional pages may attempt to steal more data or initiate unauthorized transactions. Report the domain to PhishDestroy and your wallet provider to help block its spread. Monitor your wallet for unusual activity and consider transferring remaining assets to a new wallet after verifying its security. Always verify URLs and use hardware wallets for high-value transactions to mitigate drainer risks. ## Threat Details - Verdict: SUSPICIOUS - Site status: unknown (HTTP ?) ## Domain Intelligence - Registrar: Cloudflare, Inc. - IP: 172.66.47.79 ## Detection Status - VirusTotal: 0 vendors flagged - Google Safe Browsing: clean - Blocklists: 0 hits ## Evidence - Cloudflare Radar: https://radar.cloudflare.com/domains/tronqcan.pages.dev - PhishDestroy: https://phishdestroy.io/domain/tronqcan.pages.dev/ - LLM endpoint: https://phishdestroy.io/domain/tronqcan.pages.dev/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/tronqcan.pages.dev/ Last updated: 2026-04-03