secure-us-balaner-portcol[.]pages[.]dev
“Balancer Protocol – Advanced Liquidity Pools for DeFi Traders”
secure-us-balaner-portcol.pages.dev — Doğrulanmamış. Marka kimliğine bürünme: Balancer; Dolandırıcılık türü: Brand Impersonation. Kanıt özeti: VirusTotal 3/91 (alphaMountain.ai, Fortinet, LevelBlue); PhishDestroy score 76/100. Kayıt kuruluşu: Cloudflare.
Özgün adli kaydı korumak için aşağıdaki ayrıntılı PhishDestroy AI analizi İngilizce bırakılmıştır.
PhishDestroy identifies secure-us-balaner-portcol.pages.dev as a live credential-phishing site posing as a cryptocurrency wallet or exchange login portal. Once a victim enters private keys or seed phrases, the page silently drains connected wallets to external addresses controlled by attackers. This ‘crypto drainer’ technique bypasses two-factor authentication by tricking users into surrendering their most sensitive secrets directly to the scammer’s interface. Cloudflare Pages hosting adds a veneer of legitimacy, but the underlying domain is engineered to harvest crypto credentials within seconds of form submission.
This domain was flagged after VirusTotal’s engines returned a single positive detection out of 95 scanners. The site is served from IP 172.66.47.158 and protected by a Google Trust Services certificate, yet its creation date and registrar remain obscured by Cloudflare’s privacy proxy. The unique seed 1fe666 confirms this is a fresh, purpose-built lure rather than a recycled campaign, increasing the likelihood of successful victim engagement.
If you visited secure-us-balaner-portcol.pages.dev, immediately revoke any wallet connections, transfer remaining assets to a clean wallet, and scan devices for infostealers. Do NOT enter private keys, seed phrases, or passwords on the page. Report the domain to PhishDestroy for takedown and monitor wallet transactions for outgoing transfers. Treat any device used to access the site as potentially compromised until a full antivirus scan and password reset are completed.
Ağ Güvenliği İstihbaratı
Tehdit Müdahale Pipeline
Genel Engelleme Listesi Durumu
Teknolojiler · 3 identified
HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org %100 güvenCloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com %100 güvenHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org %100 güvenVirusTotal Analizi
Arşivlenmiş Kanıtlar
Site Performans Analizi
Google PageSpeed Insights — mobile performance audit of secure-us-balaner-portcol.pages.dev · checked May 1, 2026
Kanıtlar ve Dış Raporlar
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin