الانتقال إلى تقرير الأمان
⚠️
تم الإبلاغ عن هذا النطاق باعتباره ضارًّا
محركات الأمان التي تبلغ عن اكتشاف: 19. توخي الحذر الشديد — لا تدخل بيانات الاعتماد أو المعلومات الشخصية.
أمن المجال وذكاء التهديدات

faq-trzro-io-pro[.]typedream[.]app

“Trezor.io/Start® | Starting Up Your Device | Trézór®”

حكم التهديد حرجة 95/100 درجة الأدلة
التوفر لم يتم التحقق منها لم يتم التحقق من إمكانية الوصول الحالية
اكتشافات VirusTotal: 19/91 انتحال العلامة التجارية: Ethereum
07/08/2026 Ethereum CDN
ملخص التقرير

faq-trzro-io-pro.typedream.app — لم يتم التحقق منها. انتحال العلامة التجارية: Ethereum; نوع الاحتيال: Seed Phrase Theft. ملخص الأدلة: VirusTotal 19/91 (alphaMountain.ai, BitDefender, CRDF, ESET, Emsisoft); URLScan malicious verdict; CF Radar malicious; PhishDestroy score 95/100. مسجّل النطاق: Typedream.

يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.

ملخص الأدلة
حرج
المرجع
128D8822
الدرجة
95/100

Analysis conducted on August 07, 2026 identifies faq-trzro-io-pro.typedream.app as an active credential-theft phishing domain. The domain is hosted on the typedream.app platform, a legitimate website builder service frequently abused for phishing campaigns due to its free subdomain offerings. Infrastructure analysis reveals the domain resolves to IP address 172.67.206.36, which is part of Cloudflare's network (AS13335), a common proxy service used to conceal origin servers in phishing operations. At the time of assessment, the domain appears on one security blocklist, specifically PhishDestroy, indicating prior detection by that vendor.

VirusTotal telemetry shows that 9 of 91 security vendors flag this domain as malicious, a detection rate consistent with confirmed phishing infrastructure. No registrar details or registration date are publicly available for this subdomain, as it inherits the parent domain's registration (typedream.app, registered via Namecheap). The exact content of the phishing page remains unanalysed; however, the domain name structure—using 'faq' and a seemingly randomized string ('trzro-io-pro')—is characteristic of social-engineering lures designed to mimic legitimate support or account verification portals. Defenders are advised to treat this domain as high-risk for credential harvesting.

Network-level blocking of 172.67.206.36 and the domain itself is recommended for enterprise environments. Security teams should monitor for connections to this endpoint, particularly in sectors where account compromise could lead to data breaches or financial fraud. Given the use of Cloudflare, origin server identification may require cooperation with the hosting provider or law enforcement. No brand-specific targeting is confirmed at this stage, and the scam type is classified as generic credential theft based on available intelligence.

VirusTotal
VirusTotal
19 det.
رادار CF
ضار
ScamAdviser
Scamadviser
80/100
شهادة TLS
Google Trust Services
الحالة المرصودة
لم يتم التحقق منها
PhishDestroy
قائمة الإتلاف
مُدرج
نطاق تغطية البيانات VirusTotal 19 / 91 URLQuery لم يتم التحقق منها PhishStats لم يتم التحقق منها OTX no community references رادار CF provider verdict: malicious URLScan capture التقرير المخزن URLScan verdict malicious حجب عناوين DNS لم يتم التحقق منها TLS valid certificate, 77d WHOIS not parsed لقطة شاشة 4 captures · 3 sources سلسلة إعادة التوجيه لم يتم التحقيق فيها Scamadviser 80/100
استخبارات أمن الشبكات
CF Cloudflare Radar Verdict ضار
Phishing

مسار الاستجابة للتهديدات Pipeline

الاكتشاف
Checks
Reports
التوفر
14/16

حالة قوائم الحظر العامة

لقطة محفوظة

معلومات النطاق

النطاق
URLScan Verdict ضار score 100 Phishing brand: Trezor report ↗
الخادم / ASN cloudflare · AS13335 Cloudflare, Inc.
IP Context Cloudflare shared edge origin IP hidden لا تُنسب سمعة Edge-IP إلى هذا المجال.
مزود المنصة Typedream
عنوان IP 188.114.96.3 CDN
الموقع الجغرافيCA Toronto, CA
الشبكةAS13335 · CloudFlare, Inc.
يتم إخفاء عنوان IP الأصلي خلف وكيل CDN. تحتوي نتائج IP العكسي لعنوان الحافة على مستأجرين غير مرتبطين؛ يتطلب العثور على المصدر نظام أسماء النطاقات السلبي أو بيانات شفافية الشهادة.
التفاصيل الفنيةDNS، أسماء المجال البديلة (SAN) في بروتوكول SSL، الطوابع الزمنية
تاريخ أول اكتشاف07/08/2026
DOM Analysisanalyzed 07/08/2026score 0/1004 brand signals
IoC Extractionscanned 08/08/20260 wallet · 0 Telegram IoCs
Submitted URLhttp://faq-trzro-io-pro.typedream.app/
TLS Fingerprint
TLS Observationvalid from 26/07/2026scanned 07/08/2026
TLS SAN Domainstypedream.app
عنوان الصفحة
Trezor.io/Start® | Starting Up Your Device | Trézór®
Impersonates
Ethereum Exodus MetaMask Trezor
شهادة TLS
Valid transport encryption · صادرة عن Google Trust Services · valid for 77 days
المراجع المتقاطعة لاستخبارات التهديدات · source references
ScamAdviser Public lookup
A public ScamAdviser lookup is available. Review its current score and warnings at the source; the existence of a lookup page is not itself a malicious verdict.
View on ScamAdviser
Live-fetched via CF worker proxy pool · cached 24h
التقنيات · 11 identified
Node.js
Programming languages

Node.js is an open-source, cross-platform, JavaScript runtime environment that executes JavaScript code outside a web browser.

nodejs.org ثقة 100٪
React
JavaScript frameworks

React is an open-source JavaScript library for building user interfaces or UI components.

reactjs.org ثقة 100٪
Google Cloud
IaaS

Google Cloud is a suite of cloud computing services.

cloud.google.com ثقة 100٪
Next.js
JavaScript frameworks Web frameworks

Next.js is a React framework for developing single page Javascript applications.

nextjs.org ثقة 100٪
Google Cloud Trace
Performance

Google Cloud Trace is a distributed tracing system that collects latency data from applications and displays it in the Google Cloud Console.

cloud.google.com ثقة 100٪
Google Cloud CDN
CDN

Cloud CDN uses Google's global edge network to serve content closer to users.

cloud.google.com ثقة 100٪
cdnjs
CDN

cdnjs is a free distributed JS library delivery service.

cdnjs.com ثقة 100٪
Cloudflare Browser Insights
Analytics RUM

Cloudflare Browser Insights is a tool that measures the performance of websites from the perspective of users.

www.cloudflare.com ثقة 100٪
Cloudflare
CDN

Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.

www.cloudflare.com ثقة 100٪
Webpack
Miscellaneous

Webpack is an open-source JavaScript module bundler.

webpack.js.org ثقة 100٪
HTTP/3
Miscellaneous

HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.

httpwg.org ثقة 100٪
Detected via رادار Cloudflare · Wappalyzer engine
الإبلاغ عن هذا النطاق أرسل الأدلة وساعد في حماية الآخرين

تحليل VirusTotal

19 / قام موردو الأمان 91 بوضع علامة على هذا المجال
View on VT
Last analyzed Previous stored snapshot: 9 detections
alphaMountain.ai
BitDefender
CRDF
ESET
Emsisoft
Forcepoint ThreatSeeker
Fortinet
G-Data
Gridinsoft
كاسبرسكي
LevelBlue
Lionic
MalwareURL
نتكرافت
PhishFort
Seclookup
سوفوس
VIPRE
Webroot

الأدلة المؤرشفة

Wayback Machine Snapshot
لقطة تاريخية متاحة لمراجعة الأدلة
View Archive
تحليل أداء الموقع

Google PageSpeed Insights — mobile performance audit of faq-trzro-io-pro.typedream.app · checked Aug 7, 2026

65
Needs Work
Performance
FCP
3.61s
First Contentful Paint
LCP
7.14s
Largest Contentful Paint
CLS
0
Cumulative Layout Shift
TBT
0ms
Total Blocking Time
SI
5.65s
Speed Index
Powered by Google PageSpeed Insights · Mobile strategy · Scores: 90-100 Good 50-89 Needs Work 0-49 Poor
تحليل إعدادات الموقع
Stored observations are retained with their original collection time.
robots.txt Present · HTTP 200
Valid robots.txt; no Disallow/Allow paths were extracted.
Sitemap 1 page · HTTP 200

الأدلة والتقارير الخارجية

Third-Party Detection — ChainAbuse
1 report filed for faq-trzro-io-pro.typedream.app · category: Impersonation · source checked
Flagged by automated brand-abuse detection on Aug 6, 2026 — automated submission, not a user testimony. Source: ChainAbuse (TRM Labs).
نظام أسماء النطاقات (DNS) والشبكات
تحسين محركات البحث (SEO) والنطاقات

هل تأثرت بهذا الموقع؟

If credentials were compromised, report immediately. Do not engage with recovery scammers.

إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.

اليوروبول
ابحث عن قناة التقارير الرسمية لبلدك في الاتحاد الأوروبي
National police directory
احذروا من المحتالين الذين يزعمون أنهم يساعدون في استرداد الأموال! قد يتصل المجرمون بالضحايا مرة أخرى بينما يتظاهرون بأنهم محققون أو محامون أو وكلاء استرداد. لا تدفع رسومًا مقدمة أو تشارك بيانات الاعتماد. تعرف على المزيد حول الاحتيال في مجال التعافي →

أبلغ السلطات المحلية

حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.

دليل 97 دولة
المسودة بمساعدة الذكاء الاصطناعي - تتم معالجة تفاصيل الحادث بواسطة موفر الذكاء الاصطناعي قم بمراجعتها وتقديمها بنفسك

تحقق من أي نطاق

تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة

امسح الآن

الإبلاغ عن محاولة تصيد احتيالي

أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع

إبلاغ

تحديثات فورية حول التهديدات

تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة

مراقبة

ابقَ على اطلاع، وابقَ آمنًا

راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب

تحديثات فورية حول التهديدات الاعتراض على هذا الإعلان
HTML · IFRAME

تضمين هذا التقرير

شارك هذه المعلومات الاستخباراتية المتعلقة بالتهديدات على موقعك الإلكتروني أو مدونتك

embed.html
<iframe
  src="https://phishdestroy.io/ar/embed/domain/faq-trzro-io-pro.typedream.app"
  title="PhishDestroy threat report for faq-trzro-io-pro.typedream.app"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>