# download-officaltrezrsuite.pages.dev — SUSPICIOUS > download-officaltrezrsuite.pages.dev hosts a crypto drainer impersonating Trezor Suite. Verify legitimacy on PhishDestroy. VT score 0/95 ## Summary PhishDestroy identifies download-officaltrezrsuite.pages.dev as an active crypto drainer impersonating Trezor Suite. The domain leverages a spoofed Trezor Suite branding to deceive users into connecting crypto wallets via a malicious download or interaction, enabling asset theft. This campaign targets cryptocurrency users by exploiting trust in official-branded software suites, particularly those associated with hardware wallet ecosystems. This domain resolves to IP address 172.66.44.127 and is registered through Cloudflare, Inc. The SSL certificate is issued by Google Trust Services, which does not guarantee legitimacy. As of current scans, VirusTotal reports 0 detections out of 95 engines, indicating it remains undetected by most antivirus solutions. While the domain is hosted on Cloudflare Pages, a legitimate platform, its naming convention and content are clearly malicious. The domain was recently flagged and remains under investigation with no confirmed blocklist entries at this time. The campaign is currently active, with no known takedown by hosting providers or registrars. Given the use of a crypto drainer, the risk to users who interact with the domain is high, as assets could be drained irrevocably. Users are strongly advised to verify any Trezor Suite download links via the official trezor.io domain or trusted sources. Until this domain is blocked or taken down, the risk remains elevated for cryptocurrency users seeking software downloads. PhishDestroy continues to monitor and will update intelligence as new indicators emerge. ## Threat Details - Verdict: SUSPICIOUS - Site status: unknown (HTTP ?) ## Domain Intelligence - Registrar: Cloudflare, Inc. - IP: 172.66.44.127 ## Detection Status - VirusTotal: 0 vendors flagged - Google Safe Browsing: clean - Blocklists: 0 hits ## Evidence - Cloudflare Radar: https://radar.cloudflare.com/scan/96fb2741-52fe-42e6-9bdc-9b885d8f05d5 - PhishDestroy: https://phishdestroy.io/domain/download-officaltrezrsuite.pages.dev/ - LLM endpoint: https://phishdestroy.io/domain/download-officaltrezrsuite.pages.dev/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/download-officaltrezrsuite.pages.dev/ Last updated: 2026-03-22