secure-us-balaner-portcol[.]pages[.]dev
“Balancer Protocol – Advanced Liquidity Pools for DeFi Traders”
secure-us-balaner-portcol.pages.dev — Неперевірений. Уособлення бренду: Balancer; Тип шахрайства: Brand Impersonation. Зведення доказів: VirusTotal 3/91 (alphaMountain.ai, Fortinet, LevelBlue); PhishDestroy score 76/100. Реєстратор: Cloudflare.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
PhishDestroy identifies secure-us-balaner-portcol.pages.dev as a live credential-phishing site posing as a cryptocurrency wallet or exchange login portal. Once a victim enters private keys or seed phrases, the page silently drains connected wallets to external addresses controlled by attackers. This ‘crypto drainer’ technique bypasses two-factor authentication by tricking users into surrendering their most sensitive secrets directly to the scammer’s interface. Cloudflare Pages hosting adds a veneer of legitimacy, but the underlying domain is engineered to harvest crypto credentials within seconds of form submission.
This domain was flagged after VirusTotal’s engines returned a single positive detection out of 95 scanners. The site is served from IP 172.66.47.158 and protected by a Google Trust Services certificate, yet its creation date and registrar remain obscured by Cloudflare’s privacy proxy. The unique seed 1fe666 confirms this is a fresh, purpose-built lure rather than a recycled campaign, increasing the likelihood of successful victim engagement.
If you visited secure-us-balaner-portcol.pages.dev, immediately revoke any wallet connections, transfer remaining assets to a clean wallet, and scan devices for infostealers. Do NOT enter private keys, seed phrases, or passwords on the page. Report the domain to PhishDestroy for takedown and monitor wallet transactions for outgoing transfers. Treat any device used to access the site as potentially compromised until a full antivirus scan and password reset are completed.
Розвіддані з мережевої безпеки
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Технології · 3 identified
HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 100% впевненостіCloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100% впевненостіHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% впевненостіАналіз VirusTotal
Архівні докази
Аналіз продуктивності сайту
Google PageSpeed Insights — mobile performance audit of secure-us-balaner-portcol.pages.dev · checked May 1, 2026
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога