doc-trezr-help[.]pages[.]dev
“Trezor Suite® | Starting Up Your Device | Trezor®”
Observation enregistrée
Contraste de titres observé
Résumé des preuves
This domain is flagged for elevated-risk brand impersonation targeting Trezor, a cryptocurrency hardware wallet provider. Analysis indicates the infrastructure is designed to mimic the Trezor Suite interface, specifically the device initialization process, as evidenced by the page title "Trezor Suite® | Starting Up Your Device | Trezor®". Such impersonation is commonly associated with crypto drainer schemes, where victims are tricked into entering recovery phrases or private keys, leading to unauthorized fund transfers. Infrastructure analysis reveals the domain doc-trezr-help.pages.dev was registered through Cloudflare, Inc. on April 30, 2026, an anomalous future date suggesting potential manipulation of registration records. The domain resolves to IP address 188.114.96.3 and employs technologies including HSTS, Cloudflare CDN, and HTTP/3. Security vendor detections on VirusTotal stand at 10/95, while Gridinsoft assigns a trust score of 0/100. The domain appears on one security blocklist and was actively blocked by PhishDestroy. The SSL certificate is issued by Google Trust Services, a common feature in both legitimate and malicious Cloudflare-hosted pages. Mitigation requires immediate action from cryptocurrency users and security teams. Users who interacted with this domain should assume compromise of any recovery phrases or private keys entered. Affected individuals must transfer remaining funds to a new wallet using an uncontaminated device and monitor all linked accounts for unauthorized transactions. Security teams should update blocklists to include the domain and its resolving IP (188.114.96.3), while Trezor users should verify they are accessing the official suite.trezor.io domain. Organizations should conduct retrospective log analysis for connections to doc-trezr-help.pages.dev or the associated IP to identify potential breaches. Given the crypto drainer threat model, emphasis should be placed on user education regarding recovery phrase security and the risks of interacting with unofficial wallet interfaces.
Data Coverage
Renseignements sur la sécurité réseau
Processus de réponse aux menaces Pipeline
Couverture des listes de blocage
10 sources externes surveillées · instantané du 11/08/2026
10 sources externes surveillées Aucune correspondance
Chronologie de détection
-
VirusTotal
0 → 10
Technologies
3 technologies identifiées avec une forte confiance
Analyse VirusTotal
Analyse des performances du site
Google PageSpeed Insights — mobile performance audit of doc-trezr-help.pages.dev · checked Jun 26, 2026
Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif