# ultrascalingsyncingsolxz.pages.dev — SUSPICIOUS > PhishDestroy flags ultrascalingsyncingsolxz.pages.dev as a crypto drainer that already fooled 3/95 security tools. ## Summary PhishDestroy identifies ultrascalingsyncingsolxz.pages.dev as an active crypto-draining phishing page that masquerades as a legitimate online service. When a victim connects a cryptocurrency wallet, the site silently approves malicious token-transfer permissions and drains funds in the background without further interaction. This type of attack is known as a “drainer” or “giveaway scam,” and it targets users who believe they are claiming a reward or accessing a utility tool. This domain was flagged after PhishDestroy correlated three independent signals: a VirusTotal detection ratio of 3 out of 95 participating engines, resolution to IP address 172.66.47.115, and a Cloudflare-issued SSL certificate via Google Trust Services. The hosting infrastructure (Cloudflare Pages) and certificate issuer are legitimate, but the content served under this hostname is malicious. Registrar data and creation timestamps remain obscured by Cloudflare’s privacy protections, preventing public disclosure of the scammer’s identity or exact age of the domain. If you visited ultrascalingsyncingsolxz.pages.dev—or any page prompting you to connect a wallet—immediately disconnect the wallet from your browser’s extension manager (e.g., MetaMask, Phantom). Revoke any token-approval permissions you may have granted by visiting a reputable revocation site such as revoke.cash or etherscan.io, then run a malware scan on your device. Report the domain to PhishDestroy and to your wallet provider so additional users can be warned. Never re-use seed phrases or private keys on unknown sites, and always verify URLs against official project websites before taking any wallet-related action. ## Threat Details - Verdict: SUSPICIOUS - Site status: unknown (HTTP ?) ## Domain Intelligence - Registrar: Cloudflare, Inc. - IP: 172.66.47.115 ## Detection Status - VirusTotal: 3 vendors flagged - Google Safe Browsing: clean - Blocklists: 0 hits ## Evidence - Cloudflare Radar: https://radar.cloudflare.com/scan/f52d028b-a510-4d79-95e5-18554ad735ec - PhishDestroy: https://phishdestroy.io/domain/ultrascalingsyncingsolxz.pages.dev/ - LLM endpoint: https://phishdestroy.io/domain/ultrascalingsyncingsolxz.pages.dev/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/ultrascalingsyncingsolxz.pages.dev/ Last updated: 2026-03-22