vro1qi5xe[.]pages[.]dev
“Welcome to Polygon - Layer3”
Resumo das evidências
This domain, vro1qi5xe.pages.dev, is flagged for brand impersonation targeting Polygon, a prominent blockchain network. Analysis indicates the site masqueraded as a legitimate Layer3 interface under the title 'Welcome to Polygon - Layer3,' likely designed to deploy a crypto drainer mechanism. The infrastructure leveraged Cloudflare Pages, a common hosting choice for threat actors due to its ephemeral nature and ease of deployment. No explicit drainer kit signatures were identified in initial scans, but the domain's structure and branding align with known crypto theft campaigns observed in recent months. Technical indicators reveal a VirusTotal detection score of 0/95, suggesting the domain had not yet been flagged by antivirus engines at the time of analysis. The domain was registered through Cloudflare, Inc. on December 16, 2025, and resolved to the IP address 172.66.44.76, a Cloudflare-operated endpoint. The SSL certificate was issued by Google Trust Services, a legitimate provider, which may have contributed to evading initial suspicion. Despite the clean VirusTotal record, the domain appeared on 5 security blocklists, including MetaMask, PhishDestroy, SEAL, ScamSniffer, and OISD, indicating prior detection by specialized crypto threat intelligence feeds. The site employed HTTP/3 and HSTS, technologies often used to enhance performance and security but also adopted by malicious actors to lend credibility to fraudulent pages. As of the latest assessment, the domain has been taken offline, likely following reports from security researchers or automated takedown mechanisms. However, the risk of re-emergence remains, as threat actors frequently rotate domains or repurpose infrastructure. Users who interacted with the site are advised to revoke any connected wallet permissions immediately and monitor for unauthorized transactions. Organizations should update blocklists to include this domain and its associated indicators, such as the IP address and SSL certificate details. Continuous monitoring of Cloudflare Pages-hosted domains with similar naming patterns is recommended, as this infrastructure remains a favored vector for crypto-related fraud.
Data Coverage
Pipeline de resposta a ameaças
Cobertura de listas de bloqueio
10 fontes externas monitoradas · instantâneo de 13/08/2026
7 fontes externas monitoradas Sem correspondência
Tecnologias
4 tecnologias identificadas com alta confiança
Análise do VirusTotal
Análise de desempenho do site
Google PageSpeed Insights — mobile performance audit of vro1qi5xe.pages.dev · checked Jun 26, 2026
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo