trez-suitee[.]pages[.]dev
“Trezor Suite | Best Hardware Wallet for Cold Crypto Storage (2025)”
Observation enregistrée
Contraste de titres observé
Résumé des preuves
PhishDestroy’s threat intelligence team has flagged trez-suitee.pages.dev as an active crypto drainer phishing domain under investigation. This domain mimics legitimate cryptocurrency tools—specifically targeting users by impersonating the Trezor Suite interface to siphon funds from unsuspecting victims. Upon analysis, the domain was found to resolve to IP address 188.114.97.3, a Cloudflare-hosted endpoint leveraging a Google Trust Services SSL certificate to appear legitimate. Notably, despite hosting malicious infrastructure, the domain has not yet been flagged by VirusTotal, registering 0 detections out of 95 scanners as of the latest scan. This low detection rate suggests either evasion tactics or a recent deployment, warranting immediate attention from security teams and users alike. The domain was registered through Cloudflare, Inc., a common choice for threat actors seeking anonymity and rapid deployment. While the exact creation date is not disclosed in available records, the lack of detections and active SSL certificate implies a recent go-live, likely within the last 30 days. Given its infrastructure alignment with known crypto drainer campaigns, the risk level is currently classified as active and under investigation, with potential for escalation as threat intelligence evolves. The absence of blocklist entries further underscores the urgency for proactive blocking, as traditional security controls may not yet recognize the threat. Users who have accessed trez-suitee.pages.dev should immediately cease any interaction with the site and revoke any permissions granted to cryptocurrency wallets or extensions linked to this domain. Conduct a full audit of wallet extensions, browser profiles, and transaction histories for signs of unauthorized transfers. If any funds have been drained, report the incident to local cybercrime units and the platform’s fraud team with screenshots and transaction IDs. To mitigate future exposure, block the domain and IP address 188.114.97.3 at the network perimeter, and update endpoint detection rules to flag similar Cloudflare-hosted crypto drainer campaigns. For ongoing monitoring, enable transaction alerts on all cryptocurrency accounts and avoid interacting with unsolicited links claiming to offer Trezor Suite services.
Data Coverage
Renseignements sur la sécurité réseau
Processus de réponse aux menaces Pipeline
Couverture des listes de blocage
10 sources externes surveillées · instantané du 10/08/2026
10 sources externes surveillées Aucune correspondance
Analyse forensique
Analyse VirusTotal
Analyse des performances du site
Google PageSpeed Insights — mobile performance audit of trez-suitee.pages.dev · checked Mar 25, 2026
Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif