cloud-trezor-wlt[.]pages[.]dev
“Suspected Phishing | Cloudflare”
Zusammenfassung der Beweislage
This domain, cloud-trezor-wlt.pages.dev, was first observed on June 10, 2026 when it was registered through the Cloudflare Pages service. The domain is currently classified as an active crypto drainer with an elevated risk rating. Independent analysis by PhishDestroy has already placed the domain on its blocklist, and it also appears on an additional security blocklist, indicating that at least two independent sources have deemed the site malicious. VirusTotal scans show that 11 out of 91 security vendors flagged the domain as suspicious or malicious, providing further corroboration of its abusive intent.
The hosting environment is provided by Cloudflare Pages, which supplies a shared content‑delivery infrastructure and often masks the underlying origin IP, limiting immediate attribution of the operator’s network location. No public IP address, ASN, or geographic data has been disclosed, and SSL/TLS certificate details are not publicly visible beyond the default Cloudflare certificates. Likewise, the HTTP response status and page title have not been reported, leaving the surface‑level content of the site unverified.
The limited telemetry therefore restricts a deeper technical fingerprint, but the convergence of registration timing, hosting provider, blocklist inclusion, and multi‑vendor detection strongly suggests a coordinated campaign targeting cryptocurrency users. Defenders should proactively block cloud‑trezor‑wlt.pages.dev at perimeter and DNS layers, monitor outbound connections to Cloudflare edge nodes for anomalous traffic patterns, and consider adding the domain to internal threat intel feeds. Continuous re‑evaluation is recommended, as further analysis may reveal additional indicators such as malicious scripts, credential‑phishing endpoints, or wallet‑draining payloads.
Data Coverage
Pipeline zur Reaktion auf Sicherheitsbedrohungen
Blocklistenabdeckung
10 überwachte externe Feeds · gespeicherter Stand 10.08.2026
Erkennungszeitleiste
-
Domainstatus
Erreichbar → Nicht erreichbar
Community-Meldungen
Von 1 Community-Mitglied gemeldet; erstmals gesehen am 10.06.2026
- Gespeicherte Meldungen
- 1
- Eindeutige gemeldete URLs
- 1
Community-Erkenntnisse
1 Community-Meldung
KategorieIMPERSONATION
Brand abuse: phishing, impersonation, impersonating Trezor
Domain-Intelligenz
Technische DetailsDNS, TLS-Namen und Zeitstempel
Technologien
3 Technologien mit hoher Konfidenz erkannt
VirusTotal-Analyse
Website-Performanceanalyse
Google PageSpeed Insights — mobile performance audit of cloud-trezor-wlt.pages.dev · checked Jul 29, 2026
Ähnliche Domains
74 gespeicherte ähnliche Domains
Alle anzeigen (62)
Wurden Sie von dieser Website betroffen?
Wenn Sie Kontoanmeldeinformationen, persönliche oder Zahlungsinformationen eingegeben oder eine Datei von dieser Domain heruntergeladen haben, ergreifen Sie sofort Maßnahmen. Nachfolgend finden Sie Ressourcen, die Ihnen helfen, den Vorfall zu melden und sich zu schützen.
Melden Sie sich bei Ihren örtlichen Behörden
Wählen Sie Ihr Land aus, um Offizielle Kontakte im Bereich Cyberkriminalität oder einen Beschwerdeentwurf erstellen → zu erhalten.
Jede beliebige Domain prüfen
Bedrohungsanalyse anhand gespeicherter Blocklisten, WHOIS, DNS und öffentlicher Scan-Beweise
Jetzt scannenPhishing melden
Melden Sie verdächtige Domains an unsere Bedrohungsdatenbank – schützen Sie die Community
MeldenEchtzeit-Bedrohungsfeed
Aktuelle Phishing-Meldungen und beobachtete Verfügbarkeitsänderungen
ÜberwachenBleiben Sie auf dem Laufenden, bleiben Sie sicher
Beobachten Sie aktuelle Bedrohungen oder legen Sie Widerspruch gegen diesen Eintrag ein, wenn Sie der Meinung sind, dass es sich um einen Fehlalarm handelt