io-connecte-trezur[.]pages[.]dev
“Trezor.io/start | Official Wallet Setup WalletstartedDevice®UsersManagement”
ملخص الأدلة
On 24 July 2026 analysts observed the domain io-connecte-trezur.pages.dev serving a page titled “Trezor.io/start | Official Wallet Setup WalletstartedDevice®UsersManagement”. The page title explicitly references the Trezor brand, confirming a brand‑impersonation campaign targeting users of the hardware wallet. The domain was registered on 21 February 2026 through Cloudflare, Inc., and uses Cloudflare’s default nameservers mack.ns.cloudflare.com and liv.ns.cloudflare.com. DNS resolution points to the IP address 104.21.96.1, which belongs to AS13335 Cloudflare, Inc. and is geolocated in the United States.
HTTPS is provided by a Google Trust Services / WE1 certificate, and the site enforces HSTS and HTTP/3, indicating a modern web stack. Access attempts return HTTP 403, and the site has been taken offline, but it was previously intercepted by the PhishDestroy blocklist and appears on one additional security blocklist. The Gridinsoft trust score is 0 / 100, reflecting a lack of trust. VirusTotal analysis shows that one out of ninety‑one scanning engines flagged the domain, reinforcing the suspicion of malicious intent.
No further content has been captured, and the exact phishing payload or credential‑capture mechanism remains unknown. Defenders should add io-connecte-trezur.pages.dev and its hosting IP 104.21.96.1 to network‑level deny lists, monitor Cloudflare‑originating traffic for similar patterns, and enforce strict domain‑validation controls for any URLs containing “trezor.io”. Continuous re‑scanning of the domain and its IP is advised in case the site re‑appears. Awareness campaigns should remind Trezor users to verify the official domain (trezor.io) and to avoid unsolicited links that reference wallet setup pages.
Data Coverage
مسار الاستجابة للتهديدات Pipeline
تغطية قوائم الحظر
١٠ مصادر خارجية مراقبة · لقطة محفوظة 13/08/2026
المخطط الزمني للاكتشاف
-
حالة النطاق
يمكن الوصول إليه ← يتعذر الوصول إليه
-
Cloudflare Radar
تم حفظ فحص Cloudflare Radar · فتح الفحص
الاستخبارات الجنائية الرقمية
تحليل VirusTotal
تحليل أداء الموقع
Google PageSpeed Insights — mobile performance audit of io-connecte-trezur.pages.dev · checked Apr 12, 2026
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب