web-start-trezzr[.]pages[.]dev
“Trezor Suite% | Secure Crypto Management App”
ملاحظة محفوظة
تباين العناوين المرصود
ملخص الأدلة
PhishDestroy’s automated systems flagged the domain web-start-trezzr.pages.dev as an active crypto drainer campaign. This Cloudflare Pages-hosted site mimics a legitimate software start page to trick visitors into connecting cryptocurrency wallets and signing malicious transactions that silently drain digital assets. The attacker abuses the pages.dev subdomain to gain an air of credibility, using a Google Trust Services SSL certificate to appear trustworthy while hosting the drainer payload on Cloudflare’s edge network. At the time of discovery, the domain resolved to IP 172.66.47.125 and showed zero detections on VirusTotal, indicating a novel campaign that has not yet been widely recognized by antivirus engines.
Technical indicators collected by PhishDestroy’s pipeline reveal additional risk factors. The domain was registered through Cloudflare, Inc., which is consistent with attacker preference for bulletproof hosting and fast flux infrastructure. VirusTotal currently shows 2/95 engines detecting the URL and associated payload, underscoring the evasive nature of the drainer code. The seed identifier 21fd81 links this sample to a broader cluster of Pages.dev crypto-drainer campaigns that have emerged since Q1 2024, each employing similar obfuscation techniques and impersonation lures to target crypto users.
If you visited web-start-trezzr.pages.dev or interacted with the page—especially by connecting a wallet, signing a transaction, or entering private keys—assume your digital assets may be at risk. Immediately revoke any wallet permissions granted to the site via your wallet’s connection manager or a reputable revocation service such as revoke.cash or unrekt.net. Transfer remaining assets to a clean wallet with a newly generated seed phrase, and consider that phrase compromised if you typed it anywhere on the domain. Report the incident to your wallet provider, update your security settings, and monitor on-chain activity for unauthorized transfers. Use only bookmarked or manually verified links for crypto services in the future.
Data Coverage
استخبارات أمن الشبكات
مسار الاستجابة للتهديدات Pipeline
تغطية قوائم الحظر
١٠ مصادر خارجية مراقبة · لقطة محفوظة 11/08/2026
بلاغات المجتمع
أبلغ عنه عضو واحد في المجتمع؛ شوهد أول مرة في 18/04/2026
- البلاغات المحفوظة
- 1
- عناوين URL الفريدة المبلغ عنها
- 1
معلومات المجتمع
بلاغ مجتمعي واحد
الفئةPHISHING
The PhishFort Detection System has flagged this as a domain threat, classified as phishing. Associated tags: subdomain, typosquat. Threat detected at 2026-05-01T07:29:22.987Z.
تحليل VirusTotal
تحليل أداء الموقع
Google PageSpeed Insights — mobile performance audit of web-start-trezzr.pages.dev · checked Apr 18, 2026
نطاقات متشابهة
٧٤ نطاقًا متشابهًا محفوظًا
عرض الكل (62)
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب