vro1fedw3[.]pages[.]dev
“$FAIR Token Distribution”
已存储的观测记录
观测到的标题差异
证据摘要
Domain vro1fedw3.pages.dev is currently under active analysis as a generic phishing page that functions as a crypto-asset drainer. The site impersonates a legitimate login interface to trick users into surrendering wallet credentials or signing malicious transactions. No specific brand or drainer kit fingerprint has been extracted yet; the payload remains under forensic review to identify the exact scheme and target ecosystem.
PhishDestroy’s scan shows zero detections on VirusTotal (0/95 engines) as of the latest update. The domain is registered through Cloudflare, Inc., resolves to IP 172.66.47.129, and holds a Google Trust Services SSL certificate. Creation date and additional infrastructure details are still being correlated; the site is not yet flagged on Google Safe Browsing and has not appeared on major threat-intel blocklists. These factors suggest a recently stood-up, lightly abused domain designed to evade early detection.
The campaign is flagged as active and under investigation, meaning no permanent takedown or block has been applied. Users are advised to avoid interacting with vro1fedw3.pages.dev and to verify any unexpected links via PhishDestroy before entering credentials or approving transactions. Remaining risk is elevated given the lack of third-party detections and the domain’s reliance on Cloudflare’s infrastructure to remain operational.
Data Coverage
网络安全情报
威胁响应 Pipeline
阻止列表覆盖
监控中的外部数据源 10 个 · 已存快照 2026年8月12日
VirusTotal 分析
网站性能分析
Google PageSpeed Insights — mobile performance audit of vro1fedw3.pages.dev · checked Apr 6, 2026
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。
检查任意域名
使用存储的阻止列表、WHOIS、DNS 和公共扫描证据进行威胁分析
立即扫描举报网络钓鱼
将可疑域名提交至我们的威胁数据库——保护社区
报告实时威胁动态
最近的网络钓鱼报告和观察到的可用性变化
监控