defirouter[.]us
Verificação de phishing e segurança de defirouter.us
“The Best Crypto & Binance Bridge | CrossBridge”
defirouter.us — Conteúdo indisponível (HTTP 502). Representação da marca: Binance; Tipo de golpe: Investment Scam. Resumo das evidências: VirusTotal 5/94 (G-Data, Gridinsoft, Sophos, Webroot); 3 external blocklist matches (MetaMask, ScamSniffer, SEAL); PhishDestroy score 74/100. Registrador: NameSilo.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
PhishDestroy identifies defirouter.us as an active crypto drainer domain that specifically targets cryptocurrency users by draining funds from connected wallets. This site does not merely harvest credentials; it executes sophisticated wallet-draining scripts that automatically approve and transfer tokens when victims connect their wallets. While no public information confirms a specific drainer kit or brand impersonation at this time, the deployment pattern closely resembles those leveraged by known kits such as “Venom Drainer” or “Angel Drainer,” both of which have been widely used in recent DeFi exploit campaigns. The operational behavior—silent wallet connection, unauthorized token approvals, and immediate fund redirection—confirms this is an active theft operation rather than a simple phishing portal. This domain was flagged by ScamSniffer and is currently blocked across multiple threat intelligence platforms. According to VirusTotal, defirouter.us has a security detection score of 4 out of 95 vendors, indicating limited but targeted recognition. The domain resolves to IP address 188.114.96.3, hosted on infrastructure associated with high-risk cryptocurrency scam operations. It was registered through NameSilo, LLC on April 2, 2026—an unusually recent creation date suggestive of burner hosting to avoid historical scrutiny. The SSL certificate is issued by Let's Encrypt, demonstrating an attempt to appear legitimate via encryption. It currently appears on 1 known blocklist and remains active, with no evidence of takedown as of the latest scan. Despite being flagged by ScamSniffer, the site remains accessible and continues to operate as an active crypto drainer. Given its recent creation and low detection rate on widely used scanners, defirouter.us poses an elevated risk to unsuspecting users—particularly those seeking DeFi routing solutions. PhishDestroy recommends that all users verify any DeFi-related domain using its real-time scanning tool before interaction. The remaining risk is elevated due to the site’s active status, low detection score, and strong resemblance to known wallet-draining operations. Users should treat defirouter.us as a confirmed threat and avoid all wallet connections to this domain.
Inteligência de segurança de rede Registrar context
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Inteligência forense
Análise do VirusTotal
Análise de desempenho do site
Google PageSpeed Insights — mobile performance audit of defirouter.us · checked Apr 10, 2026
Evidências e relatórios externos
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo