MALICIOUS — CRITICAL
typusfiinance[.]pages[.]dev
This domain, typusfiinance.pages.dev, is identified as a high-risk generic phishing site targeting users of Typus Finance, a decentralized finance platform.
- VirusTotal
- 1/91
- Blocklists
- 3 · MetaMask, ScamSniffer
- 可用性
- 最后已知的活跃状态 · HTTP 200
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
typusfiinance.pages.dev — 最后已知的活跃状态 (HTTP 200). 诈骗类型:Fake Exchange. 证据摘要: VirusTotal 1/91 (Gridinsoft); 3 external blocklist matches (MetaMask, ScamSniffer, SEAL); PhishDestroy score 89/100. 注册商: Cloudflare.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
Evidence Analysis
typusfiinance.pages.dev Fake Typus Finance Phishing Site
typusfiinance.pages.dev is a high-risk phishing domain impersonating Typus Finance, active since March 28, 2026.
This domain, typusfiinance.pages.dev, is identified as a high-risk generic phishing site targeting users of Typus Finance, a decentralized finance platform. Analysis indicates the site is designed to harvest credentials or facilitate unauthorized transactions, likely through a cryptocurrency drainer kit, though no specific kit has been confirmed. The domain mimics the legitimate Typus Finance branding, including its page title, to deceive visitors into interacting with malicious infrastructure. Infrastructure analysis reveals the domain was registered on March 28, 2026, through Cloudflare, Inc., and resolves to the IP address 172.66.47.188, located in California. Despite its recent creation, the domain has already been flagged by 4 security blocklists, including PhishDestroy, MetaMask, ScamSniffer, and SEAL. VirusTotal reports 0 out of 95 detections, indicating the threat may still be evading some automated detection systems. The SSL certificate is issued by Google Trust Services (WE1), providing a false sense of security to unsuspecting users. The domain remains active as of this assessment, posing an ongoing risk to individuals interacting with decentralized finance platforms. Response actions by security providers have included blocklisting, but the site continues to operate under Cloudflare's hosting infrastructure. Users are advised to avoid interaction with the domain, verify URLs before accessing financial platforms, and employ browser-based security extensions to block known phishing sites. The combination of low VirusTotal detections and high blocklist prevalence suggests this is a targeted or emerging threat requiring heightened vigilance.
Stored source results
Recorded verdicts and infrastructure observations for this domain.
数据覆盖范围12 recorded checks
网络安全情报
威胁响应 Pipeline
公共封禁名单状态
VirusTotal 分析
证据与外部报告Independent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。