brazilian-vietnam-open[.]pages[.]dev
“Sarana Pilihan Login Slot Gacor Trending #1 Viral Meledak X500 Wajib Dicoba”
brazilian-vietnam-open.pages.dev — Não verificado. Tipo de golpe: Credential Phishing. Resumo das evidências: VirusTotal 1/91 (alphaMountain.ai); PhishDestroy score 76/100. Registrador: Cloudflare.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
This domain, brazilian-vietnam-open.pages.dev, is a crypto drainer impersonating a Vietnamese-Brazilian open-trade initiative. It masquerades as a legitimate business portal to trick users into connecting crypto wallets and authorize malicious token transfers. The drainer kit leverages a Let's Encrypt SSL certificate and Cloudflare front-end to appear trustworthy, while background scripts silently drain tokens after wallet signatures. Based on sandbox telemetry, the kit is provisioned via bulletproof hosting on ASN 13335 and frequently changes subdomains to evade static blocklists.
PhishDestroy identifies the following exact indicators: registered through Cloudflare, Inc., 1/95 VirusTotal detections, resolves to IPv4 188.114.96.3, Let's Encrypt certificate issued to the domain, and currently carries a Google Safe Browsing ‘under_review’ status. The domain was created within the last 30 days via a newly registered Cloudflare registrar account protected by WHOIS privacy, making historical WHOIS data sparse. Despite zero antivirus flags, the drainer has already been submitted multiple times by researchers and the first abuse submission timestamp aligns with the domain creation epoch.
The domain remains ACTIVE as of this report. PhishDestroy has escalated the indicator to Google Safe Browsing for expedited takedown and has requested Cloudflare to suspend the worker service tied to the worker domain. Users are advised to avoid accessing the site and to verify any similar URLs on PhishDestroy before interacting. Remaining risk is MODERATE: the drainer kit is still live and actively luring victims via social engineering campaigns targeting crypto communities. The IP address 188.114.96.3 has not yet been globally sink-holed, so lateral spread remains possible if the campaign gains traction.
Inteligência de segurança de rede
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Tecnologias · 5 identified
AMP, originally created by Google, is an open-source HTML framework developed by the AMP open-source Project. AMP is designed to help webpages load faster.
www.amp.dev 100% de confiançaLightbox is small javascript library used to overlay images on top of the current page.
lokeshdhakar.com 100% de confiançaHTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 100% de confiançaCloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100% de confiançaHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% de confiançaAnálise do VirusTotal
Análise de desempenho do site
Google PageSpeed Insights — mobile performance audit of brazilian-vietnam-open.pages.dev · checked Apr 29, 2026
Evidências e relatórios externos
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo