defi-6w3r[.]pages[.]dev
“Accessing Biswap on BitKeep Wallet - BitKeep News”
証拠の概要
PhishDestroy identifies defi-6w3r.pages.dev as an active crypto drainer campaign hosting malicious payloads designed to steal cryptocurrency assets from unsuspecting users. This domain operates under Cloudflare Pages, leveraging the platform's infrastructure to evade detection while distributing drainer scripts that intercept and divert funds from connected wallets. The threat is particularly dangerous due to its use of legitimate services (Cloudflare, Google Trust Services SSL) to appear credible, making it harder for users to distinguish from genuine platforms. Technical analysis reveals the domain resolves to IP 188.114.97.3, a known hosting environment associated with malicious crypto operations, with the unique seed identifier 7d2a26 linking it to broader fraudulent campaigns targeting decentralized finance (DeFi) users. This domain exhibits multiple red flags confirmed by threat intelligence platforms. VirusTotal currently shows 0 detections out of 95 scanning engines, indicating it has evaded automated detection despite its malicious nature. Registered through Cloudflare, Inc., the domain benefits from Cloudflare's reputation for legitimate use, which threat actors exploit to bypass traditional security filters. The SSL certificate issued by Google Trust Services further enhances its perceived legitimacy, as users often associate HTTPS with safety. While the exact registration date is not provided, the domain's active status and recent operational patterns suggest it was created recently to capitalize on current DeFi trends. At present, this domain remains unlisted on major blocklists, allowing it to operate undetected by standard security measures. The combination of low detection rates, legitimate infrastructure abuse, and targeted crypto drainer functionality elevates its risk profile to a critical level for cryptocurrency users. Users who have visited defi-6w3r.pages.dev or interacted with its content should treat their digital assets as compromised. Immediately disconnect any connected cryptocurrency wallets and revoke permissions through your wallet's interface or a reputable blockchain explorer. Transfer any remaining funds to a newly generated wallet address not associated with past transactions. Scan all devices used to access this domain with updated antivirus and anti-malware software, as drainer scripts may deploy keyloggers or other surveillance tools. Report this domain to PhishDestroy via our verification portal to contribute to collective threat intelligence. Monitor your transaction history on block explorers for unauthorized transfers, and consider using hardware wallets or transaction simulation tools for future interactions with DeFi platforms. Proactive verification of domains before engagement remains the most effective defense against crypto drainer campaigns.
Data Coverage
ネットワークセキュリティインテリジェンス
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | cg-keitaro.team |
malicious | Sinkholed |
脅威対応 Pipeline
ブロックリストの確認範囲
監視対象の外部情報源 10 件 · 保存スナップショット 2026年8月13日
VirusTotalによる分析
サイトパフォーマンス分析
Google PageSpeed Insights — mobile performance audit of defi-6w3r.pages.dev · checked Apr 13, 2026
このサイトによって何か影響を受けましたか?
アカウント資格情報、個人情報、支払い情報を入力した場合、またはこのドメインからファイルをダウンロードした場合は、すぐに対処してください。インシデントを報告し、自分自身を守るのに役立つリソースを以下に示します。
お住まいの地域の当局へ報告してください
サイバー犯罪の公式連絡先 または 苦情草稿を作成する → を取得するには、国を選択してください。
任意のドメインを確認する
保存されたブロックリスト、WHOIS、DNS、および公開スキャン証拠を使用した脅威分析
今すぐスキャンフィッシングを報告する
不審なドメインを当社の脅威データベースに報告してください — コミュニティを守りましょう
レポートリアルタイム脅威情報フィード
最近のフィッシングレポートと観察された可用性の変化
監視最新情報を入手し、安全を確保しましょう
リアルタイムの脅威を監視するか、誤検知だと思われる場合はこのリストに異議を申し立ててください