cloud-trezor-wlt[.]pages[.]dev
“Suspected Phishing | Cloudflare”
Résumé des preuves
This domain, cloud-trezor-wlt.pages.dev, was first observed on June 10, 2026 when it was registered through the Cloudflare Pages service. The domain is currently classified as an active crypto drainer with an elevated risk rating. Independent analysis by PhishDestroy has already placed the domain on its blocklist, and it also appears on an additional security blocklist, indicating that at least two independent sources have deemed the site malicious. VirusTotal scans show that 11 out of 91 security vendors flagged the domain as suspicious or malicious, providing further corroboration of its abusive intent.
The hosting environment is provided by Cloudflare Pages, which supplies a shared content‑delivery infrastructure and often masks the underlying origin IP, limiting immediate attribution of the operator’s network location. No public IP address, ASN, or geographic data has been disclosed, and SSL/TLS certificate details are not publicly visible beyond the default Cloudflare certificates. Likewise, the HTTP response status and page title have not been reported, leaving the surface‑level content of the site unverified.
The limited telemetry therefore restricts a deeper technical fingerprint, but the convergence of registration timing, hosting provider, blocklist inclusion, and multi‑vendor detection strongly suggests a coordinated campaign targeting cryptocurrency users. Defenders should proactively block cloud‑trezor‑wlt.pages.dev at perimeter and DNS layers, monitor outbound connections to Cloudflare edge nodes for anomalous traffic patterns, and consider adding the domain to internal threat intel feeds. Continuous re‑evaluation is recommended, as further analysis may reveal additional indicators such as malicious scripts, credential‑phishing endpoints, or wallet‑draining payloads.
Data Coverage
Processus de réponse aux menaces Pipeline
Couverture des listes de blocage
10 sources externes surveillées · instantané du 11/08/2026
10 sources externes surveillées Aucune correspondance
Chronologie de détection
-
État du domaine
Accessible → Inaccessible
Informations sur les domaines
Détails techniquesDNS, noms TLS et horodatages
Technologies
3 technologies identifiées avec une forte confiance
Analyse VirusTotal
Analyse des performances du site
Google PageSpeed Insights — mobile performance audit of cloud-trezor-wlt.pages.dev · checked Jul 29, 2026
Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif