523daaa5[.]ngddguteetdy[.]pages[.]dev
“Trezor Suite”
523daaa5.ngddguteetdy.pages.dev — Accesible · acceso restringido (HTTP 403). Suplantación de marca: Trezor; Tipo de estafa: Seed Phrase Theft. Resumen de las pruebas: VirusTotal 13/93 (ADMINUSLabs, BitDefender, CRDF, CyRadar, Fortinet); URLScan malicious verdict; Google Safe Browsing flagged; PhishDestroy score 89/100. Registrador: Cloudflare.
El análisis detallado de PhishDestroy AI se mantiene en inglés para conservar el registro forense original.
Analysis of the domain 523daaa5.ngddguteetdy.pages.dev indicates it was actively involved in a high-risk wallet seed-phishing campaign targeting Trezor users. The domain, hosted on Cloudflare infrastructure (IP 172.66.46.236, AS13335), was registered through Cloudflare, Inc. on September 2, 2020, and uses Cloudflare nameservers (adi.ns.cloudflare.com, karl.ns.cloudflare.com). Its SSL certificate, issued by Google Trust Services (WE1), aligns with standard Cloudflare deployments but does not mitigate the phishing risk. The page title, 'Trezor Suite,' directly corresponds to the official Trezor wallet interface, confirming the intent to impersonate the brand. Google Safe Browsing classified the domain under 'social engineering,' and it was blocked by PhishDestroy, a security blocklist.
Gridinsoft assigned a trust score of 0/100, reinforcing its malicious classification. As of July 25, 2026, the domain resolves to a 403 HTTP status, suggesting it has been taken offline or restricted, though residual DNS records persist. VirusTotal detections from 13 of 93 security vendors further validate the phishing classification, with the domain linked to a seed phrase phishing kit—a common tactic for cryptocurrency wallet compromise. The exact content of the phishing page remains unconfirmed, but the combination of brand impersonation, seed-phishing classification, and blocklist inclusion provides strong evidence of malicious intent.
Defenders should treat this domain as part of a broader phishing infrastructure. While currently offline, the domain’s Cloudflare registration and historical activity warrant monitoring for reactivation. Organizations should update blocklists to include this domain and its associated IP (172.66.46.236) to prevent accidental access. No additional brand-specific indicators or victim data are available at this time.
Proceso de respuesta ante amenazas Pipeline
Estado de la lista de bloqueados pública
Tecnologías · 3 identified
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Análisis de VirusTotal
Evidencias archivadas
Análisis del rendimiento del sitio
Google PageSpeed Insights — mobile performance audit of 523daaa5.ngddguteetdy.pages.dev · checked Apr 24, 2026
Datos y informes externos
¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.