# help-trzor-dmo.pages.dev — SUSPICIOUS > PhishDestroy flags help-trzor-dmo.pages.dev as a live Trezor wallet phishing page hosted on Cloudflare Pages with 0/95 VirusTotal detections. ## Summary PhishDestroy identifies help-trzor-dmo.pages.dev as an active phishing domain designed to impersonate the legitimate Trezor cryptocurrency wallet service, tricking users into revealing their recovery phrases or private keys. The site leverages a familiar branding scheme to appear authentic at first glance, but attackers use it to harvest sensitive wallet credentials and steal digital assets. This campaign targets Trezor users who may not carefully verify domain names or SSL certificates before entering sensitive information. This domain was flagged on Cloudflare Pages and resolves to IP address 172.66.47.158, secured with a Google Trust Services SSL certificate. VirusTotal currently shows 0 detections out of 95 scans, indicating this threat remains under the radar for many security tools. The domain was registered through Cloudflare, Inc., a common choice for threat actors seeking to obscure their hosting origins while maintaining uptime reliability. If you visited help-trzor-dmo.pages.dev and entered any information, immediately transfer your remaining funds to a newly generated wallet address on the official Trezor website. Revoke any connected browser permissions and run a malware scan on your device. Report the domain to Trezor’s abuse team and consider rotating any passwords or recovery phrases used on similar services. Always verify URLs match the official Trezor domain (trezor.io) and enable two-factor authentication for added security. ## Threat Details - Verdict: SUSPICIOUS - Site status: unknown (HTTP ?) ## Domain Intelligence - Registrar: Cloudflare, Inc. - IP: 172.66.47.158 ## Detection Status - VirusTotal: 0 vendors flagged - Google Safe Browsing: clean - Blocklists: 0 hits ## Evidence - Cloudflare Radar: https://radar.cloudflare.com/scan/c41d7903-aaf4-431d-ae75-7bfd9f7a3150 - PhishDestroy: https://phishdestroy.io/domain/help-trzor-dmo.pages.dev/ - LLM endpoint: https://phishdestroy.io/domain/help-trzor-dmo.pages.dev/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/help-trzor-dmo.pages.dev/ Last updated: 2026-03-24