web-start-trezzr[.]pages[.]dev
“Trezor Suite% | Secure Crypto Management App”
Pengamatan tersimpan
Perbedaan judul yang diamati
Ringkasan bukti
PhishDestroy’s automated systems flagged the domain web-start-trezzr.pages.dev as an active crypto drainer campaign. This Cloudflare Pages-hosted site mimics a legitimate software start page to trick visitors into connecting cryptocurrency wallets and signing malicious transactions that silently drain digital assets. The attacker abuses the pages.dev subdomain to gain an air of credibility, using a Google Trust Services SSL certificate to appear trustworthy while hosting the drainer payload on Cloudflare’s edge network. At the time of discovery, the domain resolved to IP 172.66.47.125 and showed zero detections on VirusTotal, indicating a novel campaign that has not yet been widely recognized by antivirus engines.
Technical indicators collected by PhishDestroy’s pipeline reveal additional risk factors. The domain was registered through Cloudflare, Inc., which is consistent with attacker preference for bulletproof hosting and fast flux infrastructure. VirusTotal currently shows 2/95 engines detecting the URL and associated payload, underscoring the evasive nature of the drainer code. The seed identifier 21fd81 links this sample to a broader cluster of Pages.dev crypto-drainer campaigns that have emerged since Q1 2024, each employing similar obfuscation techniques and impersonation lures to target crypto users.
If you visited web-start-trezzr.pages.dev or interacted with the page—especially by connecting a wallet, signing a transaction, or entering private keys—assume your digital assets may be at risk. Immediately revoke any wallet permissions granted to the site via your wallet’s connection manager or a reputable revocation service such as revoke.cash or unrekt.net. Transfer remaining assets to a clean wallet with a newly generated seed phrase, and consider that phrase compromised if you typed it anywhere on the domain. Report the incident to your wallet provider, update your security settings, and monitor on-chain activity for unauthorized transfers. Use only bookmarked or manually verified links for crypto services in the future.
Data Coverage
Intelijen Keamanan Jaringan
Alur Tanggapan Ancaman Pipeline
Cakupan daftar blokir
10 sumber eksternal dipantau · snapshot tersimpan 11/08/2026
Laporan komunitas
Dilaporkan oleh 1 anggota komunitas; pertama terlihat 18/04/2026
- Laporan tersimpan
- 1
- URL unik yang dilaporkan
- 1
Intelijen komunitas
1 laporan komunitas
KategoriPHISHING
The PhishFort Detection System has flagged this as a domain threat, classified as phishing. Associated tags: subdomain, typosquat. Threat detected at 2026-05-01T07:29:22.987Z.
Analisis VirusTotal
Analisis Performa Situs
Google PageSpeed Insights — mobile performance audit of web-start-trezzr.pages.dev · checked Apr 18, 2026
Domain serupa
74 domain serupa tersimpan
Tampilkan semua (62)
Apakah Anda Terpengaruh oleh Situs Ini?
Jika Anda memasukkan kredensial akun, informasi pribadi atau pembayaran, atau mengunduh file dari domain ini, segera ambil tindakan. Di bawah ini adalah sumber daya untuk membantu Anda melaporkan insiden tersebut dan melindungi diri Anda sendiri.
Laporkan kepada Pihak Berwenang di Daerah Anda
Pilih negara Anda untuk mendapatkan kontak resmi kejahatan dunia maya, atau membuat draf pengaduan →.
Periksa Domain Apa Pun
Analisis ancaman menggunakan daftar blokir yang disimpan, WHOIS, DNS, dan bukti pemindaian publik
Pindai SekarangLaporkan Phishing
Laporkan domain yang mencurigakan ke basis data ancaman kami — lindungi komunitas
LaporanPemberitahuan Ancaman Real-Time
Laporan phishing terbaru dan perubahan ketersediaan yang diamati
PantauTetap Terinformasi, Tetap Aman
Pantau ancaman secara langsung atau ajukan keberatan terhadap daftar ini jika Anda yakin ini merupakan false positive