paybis-lgin[.]pages[.]dev
Verifica phishing e sicurezza per paybis-lgin.pages.dev
“Paybis Login – Secure Cryptocurrency Exchange Access”
paybis-lgin.pages.dev — Raggiungibile · accesso limitato (HTTP 403). Tipo di truffa: Fake Exchange. Riepilogo delle prove: VirusTotal 4/91 (ChainPatrol, Emsisoft, Netcraft, Webroot); 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 66/100. Registrar: Cloudflare.
L’analisi dettagliata di PhishDestroy AI resta in inglese per preservare il rapporto forense originale.
Evidence Analysis
PhishDestroy analyzed paybis-lgin.pages.dev, a generic phishing domain impersonating Paybis to steal login credentials. The site's title, 'Paybis Login – Secure Cryptocurrency Exchange Access,' was designed to deceive users into entering sensitive information. While no specific drainer kit was identified, the threat model suggests credential harvesting with potential for cryptocurrency theft.
Technical indicators reflect a sophisticated operation. Created on October 31, 2025, the domain was registered through Cloudflare, Inc., and resolved to IP 188.114.97.3. VirusTotal flagged it with a 4/95 detection ratio, and it appeared on three security blocklists. The SSL certificate, issued by Google Trust Services/WE1, provided a veneer of legitimacy. Notably, the domain was not listed on Google Safe Browsing at the time of analysis.
As of this report, the domain has been taken offline, reducing immediate risk. However, similar variants may emerge. Users who entered credentials should reset passwords immediately, enable two-factor authentication on all cryptocurrency accounts, and monitor for unauthorized transactions. PhishDestroy recommends vigilance against lookalike domains, especially those with subtle misspellings or different top-level domains, and advises verifying URLs directly through official channels before logging in.
Copertura dei dati12 recorded checks
Pipeline di risposta alle minacce
Stato della lista di blocco pubblica
Tecnologie · 3 identified
HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org Confidenza al 100%Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com Confidenza al 100%HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org Confidenza al 100%Analisi di VirusTotal
Dati e relazioni esterneIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.