biswapmain[.]pages[.]dev
“Biswap – Freedom of exchange”
Observação armazenada
Contraste de títulos observado
Resumo das evidências
PhishDestroy identifies an active crypto drainer campaign operating from the domain biswapmain.pages.dev, currently classified as a high-risk threat under seed 89cd54. This fraudulent site mimics the legitimate Biswap platform, aiming to trick users into connecting crypto wallets and draining funds. Unlike generic phishing pages, this domain employs a crypto-specific attack vector designed to exploit user trust in decentralized finance (DeFi) interfaces. The threat actor leverages Cloudflare Pages to host the phishing kit, ensuring rapid deployment and evasion of early detection systems. With no detections recorded on VirusTotal as of this report, the domain remains under active circulation, targeting cryptocurrency users who may overlook verification steps. The SSL certificate issued by Google Trust Services adds superficial legitimacy, while the underlying infrastructure resolves to Cloudflare IP 172.66.47.4, a known hosting range for malicious campaigns. This domain was flagged within 24 hours of its registration, with VirusTotal showing 0 detections across 95 scanning engines—indicating that signature-based defenses have not yet caught up to this threat. The domain biswapmain.pages.dev was registered through Cloudflare, Inc., a common tactic among threat actors seeking to obscure their identity behind anonymized registrations. Cloudflare Pages, the platform used to host this campaign, allows for quick setup of phishing pages that bypass traditional web hosting scrutiny. The domain’s recent creation and lack of detections highlight the importance of proactive threat intelligence; by the time automated defenses catch up, users may have already fallen victim. The use of a legitimate-looking subdomain (pages.dev) further lowers suspicion, appealing to users who may not inspect the URL closely. If you visited biswapmain.pages.dev or entered any credentials or connected a wallet, immediately disconnect your wallet from the site and revoke any unauthorized permissions through your wallet’s connected apps menu. Do not interact with any prompts or transaction requests originating from this domain. Use a separate browser profile or device for DeFi activities and enable hardware wallet signing where possible. Report the domain to PhishDestroy for takedown and share any transaction hashes or wallet addresses linked to this site to aid in tracking the threat actor. Monitor your wallet’s transaction history for unauthorized transfers and consider transferring remaining funds to a cold wallet if suspicious activity is detected. Always verify URLs against official sources and never follow links from unsolicited messages or third-party advertisements.
Data Coverage
Inteligência de segurança de rede
Pipeline de resposta a ameaças
Cobertura de listas de bloqueio
10 fontes externas monitoradas · instantâneo de 11/08/2026
10 fontes externas monitoradas Sem correspondência
Inteligência forense
Análise do VirusTotal
Análise de desempenho do site
Google PageSpeed Insights — mobile performance audit of biswapmain.pages.dev · checked Mar 30, 2026
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo