prelix-klavor-biz-hendix-grentor-sp7ct12[.]pages[.]dev
“Suspected phishing site | Cloudflare”
prelix-klavor-biz-hendix-grentor-sp7ct12.pages.dev — 콘텐츠를 사용할 수 없음. 사기 유형: Credential Phishing. 증거 요약: VirusTotal 13/94 (Criminal IP, BitDefender, CyRadar, ESET, Emsisoft); PhishDestroy score 99/100. 등록기관: Cloudflare.
원본 포렌식 기록을 보존하기 위해 아래의 상세 PhishDestroy AI 분석은 영어로 유지됩니다.
PhishDestroy identifies prelix-klavor-biz-hendix-grentor-sp7ct12.pages.dev as a live crypto drainer phishing domain designed to trick users into connecting cryptocurrency wallets and authorize malicious transactions. The site impersonates legitimate crypto services by leveraging Cloudflare Pages hosting and a Google Trust Services SSL certificate to appear authentic. Threat actors utilize randomized subdomains (prelix-klavor-biz-hendix-grentor-) with appended tokens (sp7ct12) to evade detection and scale operations across multiple fraudulent projects. Analysis shows the domain resolves to IP 172.66.47.195 and has been active in the threat landscape since its creation through Cloudflare, Inc., which serves as both hosting provider and domain registrar to obscure true ownership. This domain poses an elevated risk due to its confirmed malicious status across multiple security platforms. PhishDestroy’s threat intelligence confirms that 11 out of 95 VirusTotal security vendors classify this domain as malicious, while it appears on 1 public blocklist and is directly blocked by OpenPhish, a leading phishing intelligence feed. The use of Cloudflare Pages for hosting enables rapid deployment and takedown evasion, while the Google Trust Services SSL certificate increases user trust, making it more likely that victims will interact with the page and connect their wallets. The combination of high-risk infrastructure, low detection variability across vendors, and active blocking by reputable feeds confirms this as a targeted crypto drainer operation. Users who have visited this domain should immediately disconnect their cryptocurrency wallets and revoke any unauthorized permissions granted through wallet interfaces such as MetaMask or Phantom. Run a full antivirus scan on any device used to access the site, and consider generating a new wallet address and moving funds to a cold storage solution if unauthorized transactions are suspected. PhishDestroy recommends checking the domain status on PhishDestroy’s real-time database before engaging with any crypto-related service, especially those involving wallet connections or token transfers. Never approve transactions from unknown websites, and verify URLs through official project channels. Educate team members and family about this threat, as crypto drainers often impersonate popular NFT marketplaces, DeFi platforms, or airdrop campaigns.
네트워크 보안 인텔리전스
위협 대응 Pipeline
공개 차단 목록 상태
포렌식 인텔리전스
VirusTotal 분석
사이트 성능 분석
Google PageSpeed Insights — mobile performance audit of prelix-klavor-biz-hendix-grentor-sp7ct12.pages.dev · checked Apr 10, 2026
증거 및 외부 보고서
이 사이트로 인해 영향을 받으셨나요?
계정 자격 증명, 개인 정보 또는 결제 정보를 입력했거나 이 도메인에서 파일을 다운로드한 경우 즉시 조치를 취하세요. 다음은 사건을 신고하고 자신을 보호하는 데 도움이 되는 리소스입니다.
지역 당국에 신고하십시오
공식 사이버 범죄 연락처 또는 불만사항 초안 작성 →를 받으려면 국가를 선택하세요.