MALICIOUS — CRITICAL
coni-8ih[.]pages[.]dev
PhishDestroy identifies coni-8ih.pages.dev as a high-risk crypto drainer specifically designed to impersonate Polymarket, a popular prediction market platform.
- VirusTotal
- 10/91
- Blocklists
- 3 · MetaMask, ScamSniffer
- Disponibilità
- Contenuto non disponibile · HTTP 502
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
coni-8ih.pages.dev — Contenuto non disponibile (HTTP 502). Simulazione del marchio: Polymarket; Tipo di truffa: Crypto Drainer. Riepilogo delle prove: VirusTotal 10/91 (ADMINUSLabs, ChainPatrol, BitDefender, ESET, Emsisoft); URLScan malicious verdict; 3 external blocklist matches (MetaMask, ScamSniffer, SEAL); PhishDestroy score 80/100. Registrar: Cloudflare.
L’analisi dettagliata di PhishDestroy AI resta in inglese per preservare il rapporto forense originale.
Evidence Analysis
PhishDestroy identifies coni-8ih.pages.dev as a high-risk crypto drainer specifically designed to impersonate Polymarket, a popular prediction market platform. This threat type uses fake early access pages to trick users into connecting their crypto wallets, ultimately draining funds. The domain is now offline but remains a serious indicator of ongoing targeted attacks.
The domain was created on April 03, 2026, and resolves to IP 188.114.97.3, registered through Cloudflare, Inc. VirusTotal analysis shows 10 out of 95 security vendors flagging this domain as malicious, and it appears on 4 separate security blocklists. These indicators, combined with its short lifespan and targeted branding, confirm a coordinated phishing campaign. The trust score is critically low, and the domain's current offline status suggests it was taken down after detection.
To protect against crypto drainers like this one, users should always verify URLs by typing known addresses directly into browsers rather than clicking links. Never connect a wallet to an unfamiliar site, especially one promising early access. Enable two-factor authentication and use a hardware wallet for large holdings. Report any similar domains to security teams and blocklist providers. Vigilance is key as attackers continuously register new lookalike domains.
Copertura dei dati12 recorded checks
Pipeline di risposta alle minacce
Stato della lista di blocco pubblica
Tecnologie · 3 identified
HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org Confidenza al 100%Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com Confidenza al 100%HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org Confidenza al 100%Analisi di VirusTotal
Dati e relazioni esterneIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.