# wel-tersor-suites.pages.dev — SUSPICIOUS > wel-tersor-suites.pages.dev is a crypto drainer scam detected by PhishDestroy. VirusTotal shows 0/95 detections. Avoid connecting wallets. Learn more now. ## Summary PhishDestroy identifies wel-tersor-suites.pages.dev as an active crypto drainer posing as a luxury hotel suite booking platform. This domain is currently under investigation for deploying malicious scripts designed to drain cryptocurrency wallets upon wallet connection, a tactic commonly associated with crypto drainer scams. The threat level is classified as active but under review, indicating confirmed malicious behavior pending further categorization. This domain was flagged with a specific threat type of crypto drainer scam. Intelligence reveals it is registered through Cloudflare, Inc., resolves to IP 188.114.97.3, and holds a Google Trust Services SSL certificate. VirusTotal currently reports 0 out of 95 security engines detecting the domain, which may indicate either evasion techniques or a recently deployed threat. The domain is hosted on Cloudflare Pages, a common service abused by threat actors to rapidly deploy and rotate malicious infrastructure. Despite the lack of detections, the domain’s configuration and behavioral indicators align with known crypto drainer campaigns targeting users through deceptive booking or service websites. To mitigate risk, users are strongly advised never to connect cryptocurrency wallets to unknown or untrusted websites. Always verify the legitimacy of a site by checking official domains, using wallet connection filters like Revoke.cash, and avoiding suspicious links shared via email or social media. If interaction with this domain has already occurred, immediately revoke any connected wallet permissions and transfer remaining assets to a secure wallet. Report the domain to PhishDestroy and relevant cybersecurity platforms to aid in blocking and investigation. ## Threat Details - Verdict: SUSPICIOUS - Site status: unknown (HTTP ?) ## Domain Intelligence - Registrar: Cloudflare, Inc. - IP: 188.114.97.3 ## Detection Status - VirusTotal: 0 vendors flagged - Google Safe Browsing: clean - Blocklists: 0 hits ## Evidence - Cloudflare Radar: https://radar.cloudflare.com/scan/9fa6e867-fb0b-414e-a39a-5318bc9522dd - PhishDestroy: https://phishdestroy.io/domain/wel-tersor-suites.pages.dev/ - LLM endpoint: https://phishdestroy.io/domain/wel-tersor-suites.pages.dev/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/wel-tersor-suites.pages.dev/ Last updated: 2026-03-22