dev-en-us-io-trez[.]pages[.]dev
“Trezor login® | Secure Access to Your Trezor Wallet”
ملاحظة محفوظة
تباين العناوين المرصود
ملخص الأدلة
PhishDestroy identifies the domain dev-en-us-io-trez.pages.dev as a currently active crypto wallet drainer posing as a legitimate software update or development portal. This site is one of many in a fast-evolving campaign that lures users with promises of the latest tools while silently draining funds from connected wallets. The domain leverages Cloudflare Pages hosting and a Google Trust Services SSL certificate to appear legitimate, masking its malicious intent behind a veneer of technical authenticity. The infrastructure resolves to IP 188.114.96.3, a known hosting range used by several active drainer families. At the time of analysis, VirusTotal scans returned zero detections across 95 engines, highlighting how new variants evade signature-based detection. This domain was registered through Cloudflare, Inc., a common tactic used by threat actors to obscure true ownership and abuse legitimate hosting services for malicious purposes. While the registrar and SSL provider are not inherently malicious, their services are being exploited to deliver cryptocurrency drainers with minimal friction. The combination of a fresh domain, low detection rate, and abuse of reputable infrastructure creates a high-risk threat vector for unsuspecting users, particularly those seeking development tools or software updates. This domain represents a specific form of digital fraud known as a cryptocurrency drainer, designed to detect and exploit connected blockchain wallets during a single transaction. Unlike traditional phishing pages that harvest credentials, drainers actively monitor wallet activity and initiate unauthorized transfers to attacker-controlled addresses. PhishDestroy’s automated analysis reveals that dev-en-us-io-trez.pages.dev has not yet appeared on major threat intelligence blocklists, and VirusTotal detection remains at 5/95, indicating it is likely in the early stages of deployment. The domain is registered through Cloudflare, Inc., a legitimate hosting provider exploited by malicious actors to rapidly deploy and obscure malicious infrastructure. The assigned IP address, 188.114.96.3, is part of a larger Cloudflare IP range associated with multiple active drainer campaigns targeting crypto users globally. These technical indicators suggest an ongoing, adaptive threat that is rapidly evolving to bypass detection systems, making it particularly dangerous for cryptocurrency holders and developers. If you visited dev-en-us-io-trez.pages.dev or entered any wallet information, immediately disconnect your wallet, revoke any unauthorized permissions, and transfer remaining funds to a new wallet. Do not approve any unexpected transactions or connect to unknown domains in the future. PhishDestroy recommends using hardware wallets and limiting exposure of private keys to trusted platforms only. For ongoing protection, scan your device using updated antivirus software and monitor wallet activity for irregular transactions. Always verify URLs via official sources and avoid downloading software from untrusted or unfamiliar domains. This domain should be treated as actively hostile and blocked at the network level wherever possible. Users who suspect exposure are encouraged to report the incident to PhishDestroy for further analysis and support.
Data Coverage
استخبارات أمن الشبكات
مسار الاستجابة للتهديدات Pipeline
تغطية قوائم الحظر
١٠ مصادر خارجية مراقبة · لقطة محفوظة 12/08/2026
التقنيات
حُدّدت ٣ تقنيات عالية الثقة
تحليل VirusTotal
تحليل أداء الموقع
Google PageSpeed Insights — mobile performance audit of dev-en-us-io-trez.pages.dev · checked May 1, 2026
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب