deefi--balancer-access[.]pages[.]dev
Перевірка домену deefi--balancer-access.pages.dev на фішинг і безпеку
“Balancer® DeFi — Login, Exchange, and Troubleshooting Guide”
deefi--balancer-access.pages.dev — Останній відомий активний (HTTP 200). Уособлення бренду: Balancer; Тип шахрайства: Fake Exchange. Зведення доказів: VirusTotal 9/91 (alphaMountain.ai, BitDefender, ESET, Fortinet, G-Data); PhishDestroy score 92/100. Реєстратор: Cloudflare.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
PhishDestroy identifies deefi--balancer-access.pages.dev as an active brand impersonation phishing domain targeting Balancer users. The domain mimics Balancer’s branding to deceive victims into entering credentials or connecting wallets, likely as part of a drainer kit designed to siphon cryptocurrency assets. The infrastructure is hosted on Cloudflare Pages, leveraging Google Trust Services SSL certificates to appear legitimate. This domain was flagged due to its high-risk impersonation tactics and lack of verifiable connection to Balancer’s official domains.
Technical indicators reveal this domain was registered via Cloudflare, Inc., resolving to IP 188.114.96.3 with a VirusTotal detection score of 4/95 as of the latest scan. The domain uses a Google Trust Services SSL certificate, which may help it bypass basic browser warnings. At the time of analysis, this domain remains unblocked by major security vendors, including Google Safe Browsing (GSB), and has not been flagged on any known blocklists. The lack of detections suggests this campaign is either newly deployed or employs evasion techniques to avoid signature-based detection.
The current status of deefi--balancer-access.pages.dev is active, with an under_investigation risk level pending further analysis. Immediate recommendations include blocking the domain at the network level and advising users to avoid interacting with unsolicited links. While the immediate risk is mitigated by low detection rates, the threat remains significant due to its potential to deceive users. Security teams should monitor for associated wallet addresses or drainer scripts linked to this domain. Remaining risk is classified as high due to the likelihood of future iterations or related infrastructure deployment.
Розвіддані з мережевої безпеки
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Технології · 3 identified
HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 100% впевненостіCloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100% впевненостіHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% впевненостіАналіз VirusTotal
Аналіз продуктивності сайту
Google PageSpeed Insights — mobile performance audit of deefi--balancer-access.pages.dev · checked May 1, 2026
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога