# virto.subrezarsutese.beauty — MALICIOUS > PhishDestroy warns: virto.subrezarsutese.beauty is a crypto drainer scam, flagged by 15 of 95 VirusTotal vendors. Verify safety now. ## Summary PhishDestroy identifies virto.subrezarsutese.beauty as an active crypto drainer phishing domain currently leveraging deceptive tactics to steal cryptocurrency assets. This domain was flagged by 15 of 95 VirusTotal security vendors, indicating elevated risk and confirming its presence on 2 established blocklists. Registered through NAMECHEAP INC on February 23, 2026, the domain resolves to IP address 104.21.36.121 and holds a valid Let’s Encrypt SSL certificate. Blocked by OpenPhish and PhishingArmy, this domain exhibits high-risk indicators and should be avoided entirely. The threat remains active and poses an immediate risk to users engaging with this domain. PhishDestroy recommends blocking access, avoiding any interaction, and verifying unknown domains using its free threat verification tool. Users who suspect exposure should scan their wallets for unauthorized transactions and report suspicious activity immediately. ## Threat Details - Verdict: MALICIOUS - Site status: unknown (HTTP ?) ## Domain Intelligence - Registered: 2026-02-23 17:47:15 - Registrar: NAMECHEAP INC - IP: 104.21.36.121 ## Detection Status - VirusTotal: 15 vendors flagged - Google Safe Browsing: clean - Blocklists: 2 hits Lists: ["OpenPhish", "PhishingArmy"] ## Evidence - Cloudflare Radar: https://radar.cloudflare.com/scan/25e3d095-e527-4a5e-b6ea-6488549535bd - PhishDestroy: https://phishdestroy.io/domain/virto.subrezarsutese.beauty/ - LLM endpoint: https://phishdestroy.io/domain/virto.subrezarsutese.beauty/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/virto.subrezarsutese.beauty/ Last updated: 2026-04-12