portalbot-command[.]pages[.]dev
“Multiverse Deep Sync - One wallet, multiverse support”
Osservazione memorizzata
Contrasto dei titoli osservato
This domain, portalbot-command.pages.dev, is identified as a crypto wallet drainer phishing site designed to compromise digital asset wallets under the guise of "Multiverse Deep Sync" functionality. The page title, "Multiverse Deep Sync - One wallet, multiverse support," suggests a fraudulent service promising cross-chain wallet compatibility, a common tactic to lure users into connecting wallets to malicious smart contracts. Once connected, these drainers automatically execute unauthorized transactions, transferring cryptocurrency to attacker-controlled addresses without user consent. The threat specifically targets users of multichain wallets, exploiting their need for interoperability across blockchain networks. Analysis indicates the domain was registered through Cloudflare, Inc., on March 24, 2026, and resolves to the IP address 172.66.44.88. As of the latest scan, the domain has 0 detections out of 95 engines on VirusTotal, indicating it has not yet been widely flagged by security vendors. However, it appears on at least one security blocklist and has been assigned a trust score of 0/100 by Gridinsoft. The site employs HSTS, Cloudflare CDN, and HTTP/3, suggesting an attempt to mimic legitimate infrastructure while evading detection. The SSL certificate is issued by Google Trust Services, adding a layer of apparent legitimacy to the phishing page. Users who visited portalbot-command.pages.dev and connected a wallet should immediately disconnect the wallet from all dApps via their wallet settings. They should then revoke any suspicious smart contract approvals using a blockchain explorer or a dedicated revocation tool. It is critical to transfer remaining assets to a new, secure wallet and monitor transaction history for unauthorized activity. If credentials or seed phrases were entered, the compromised wallet should be considered permanently compromised. Users are advised to report the domain to their wallet provider and relevant security teams to aid in broader mitigation efforts.
Informazioni sulla sicurezza di rete
Pipeline di risposta alle minacce
Copertura delle blocklist
10 fonti · sincronizzato il 10/08/2026
Cronologia del rilevamento
Osservazioni memorizzate in ordine cronologico.
-
VirusTotal
VirusTotal: 6 → 0
Informazioni forensi
Analisi di VirusTotal
Analisi delle prestazioni del sito
Google PageSpeed Insights — mobile performance audit of portalbot-command.pages.dev · checked Jun 26, 2026
Questo sito ti ha influenzato in qualche modo?
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.
Verifica qualsiasi dominio
Analisi delle minacce utilizzando blocklist archiviate, WHOIS, DNS e prove di scansione pubblica
Scansiona oraSegnala un tentativo di phishing
Segnala i domini sospetti al nostro database delle minacce — proteggi la comunità
SegnalaFeed in tempo reale sulle minacce
Segnalazioni recenti di phishing e modifiche osservate della disponibilità
MonitoraRimani informato, rimani al sicuro
Controlla le minacce in tempo reale oppure contesta questa segnalazione se ritieni che si tratti di un falso positivo