erswearbtxtyuoomniubyutcrtbxt[.]pages[.]dev
“Suspected phishing site | Cloudflare”
erswearbtxtyuoomniubyutcrtbxt.pages.dev — 内容不可用. 品牌冒充:Genericcrypto; 诈骗类型:Credential Phishing. 证据摘要: VirusTotal 12/94 (ADMINUSLabs, BitDefender, CyRadar, Ermes, ESET); URLScan malicious verdict; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 91/100. 注册商: Cloudflare.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
PhishDestroy identifies the active domain erswearbtxtyuoomniubyutcrtbxt.pages.dev as a generic phishing resource currently under investigation for crypto drainer operations. This Cloudflare-hosted page mimics legitimate branding through obfuscated subdomain strings, a common tactic among drainer kits. No specific drainer signature or impersonated brand has been confirmed, but the domain exhibits red-flag URL patterns consistent with cryptocurrency wallet exfiltration campaigns. This domain resolves to IP 172.66.47.120 and operates under a Google Trust Services SSL certificate, which may be leveraged to bypass browser security warnings. VirusTotal analysis shows 0 detections out of 95 scanners as of seed 5b1fba, indicating low current signature coverage. Registered through Cloudflare, Inc., the page remains unlisted on major blocklists and lacks historical detections, suggesting a recently deployed campaign. Current status remains active with under-investigation classification. PhishDestroy advises users to avoid interaction and verify domains via its platform. Remaining risk is elevated due to zero VT detections and active infrastructure, warranting heightened caution for cryptocurrency-related links.
网络安全情报
威胁响应 Pipeline
公共封禁名单状态
取证情报
VirusTotal 分析
存档证据
网站性能分析
Google PageSpeed Insights — mobile performance audit of erswearbtxtyuoomniubyutcrtbxt.pages.dev · checked Apr 3, 2026
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。