# PhishDestroy threat dossier — find-trezo-bridge.square.site ================================================================ Fetched: 2026-07-22 18:04:28 UTC Canonical: https://phishdestroy.io/domain/find-trezo-bridge.square.site/ ## VERDICT ---------------------------------------------------------------- CRITICAL THREAT — DO NOT VISIT Composite threat score: 100/100 (PhishDestroy scoring — see methodology below) Scam classification: Impersonation Targeted brand: Trezor ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 4/91 security vendors flagged this domain Flagging vendors: ChainPatrol, alphaMountain.ai, LevelBlue, PhishFort Public blocklists: listed on 3 independent blocklists ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 74.115.51.4 (US, Oakland) ASN: AS27647 Weebly, Inc. Hosting org: Weebly, Inc. Registrar: MarkMonitor Inc. Nameservers: ["ns-1248.awsdns-28.org", "ns-1816.awsdns-35.co.uk", "ns-311.awsdns-38.com", "ns-810.awsdns-37.net"] Page title: Trezor Bridge | Connect Your Trezor Wallet Securely HTTP response: 200 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / YE2 Expires: 2026-10-03 Status: INVALID chain Fingerprint: 2409b45b254819793d9c558542323d21d5340f0e444a50a275a3462d6fbe7ef0 Subject Alternative Names (related infrastructure — often same operator): - square.site ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- First detected: 2026-07-19 12:38:12 UTC (by PhishDestroy tracker) Last verified: 2026-07-22 16:20:25 UTC Current status: ACTIVE / observable ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-20 01:04:19 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] Is find-trezo-bridge.square.site a Trezor Wallet Phishing Scam? Analysis of the domain find-trezo-bridge.square.site, registered through MarkMonitor Inc., indicates active brand impersonation targeting Trezor, a cryptocurrency hardware wallet provider. The domain resolves to IP address 74.115.51.4, hosted under Weebly, Inc. infrastructure in the United States, with nameservers managed by AWS (ns-1248.awsdns-28.org, ns-1816.awsdns-35.co.uk, ns-311.awsdns-38.com, and ns-719.awsdns-25.net). The page title, 'Trezor Bridge | Connect Your Trezor Wallet Securely,' directly mimics official Trezor communication channels, suggesting an intent to deceive users into interacting with fraudulent wallet connection prompts. As of July 19, 2026, the domain remains active with an HTTP 200 status, and its SSL certificate is issued by Let's Encrypt (identifier YE2). Security vendor detection on VirusTotal shows 4 of 91 engines flagging the domain, while three independent blocklists—PhishDestroy, MetaMask, and SEAL—have classified it as malicious. The combination of brand-specific phrasing, active hosting, and partial vendor detection supports a high-risk classification. Defenders should prioritize blocking this domain at the DNS and network levels, particularly in environments where cryptocurrency-related services are accessed. Given the domain's association with a known brand and its presence on multiple blocklists, user awareness campaigns should emphasize verifying official Trezor URLs before entering credentials or connecting wallets. Further investigation into the site's backend behavior is recommended to assess potential credential harvesting or wallet-draining mechanisms. ## EVIDENCE HASHES ---------------------------------------------------------------- Favicon MD5: 1df00d3ead9029335026790624b90508 TLS cert SHA-256: 2409b45b254819793d9c558542323d21d5340f0e444a50a275a3462d6fbe7ef0 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/find-trezo-bridge.square.site/ JSON API: https://api.destroy.tools/v1/check?domain=find-trezo-bridge.square.site Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 188,286 domains (57,731 alive under monitoring, 128,922 confirmed takedowns/dead). Site: https://phishdestroy.io