begin-bridge-trzar-io[.]pages[.]dev
“Trezor Bridge — Secure Device Communication”
Osservazione memorizzata
Contrasto dei titoli osservato
Riepilogo delle prove
PhishDestroy identifies the domain begin-bridge-trzar-io.pages.dev as hosting an active cryptocurrency drainer impersonating a bridge service. The threat is classified as generic_phishing with a current risk level of under_investigation. This domain remains active as of the latest assessment and is engineered to deceive users into connecting wallets or transferring assets to attacker-controlled addresses.
This domain was flagged by 2 of 95 VirusTotal vendors at the time of analysis, indicating limited detection despite its malicious operations. The domain is registered through Cloudflare, Inc. and resolves to IP address 172.66.47.11. It operates under Google Trust Services SSL certificates, leveraging legitimate certificate authorities to appear trustworthy. The page is hosted on Cloudflare Pages, a platform often abused by threat actors to rapidly deploy phishing infrastructure. Despite the lack of detection, the absence of historical blocklist entries and neutral reputation scores suggest this campaign is either newly deployed or carefully evasive in nature.
Users are strongly advised to avoid interacting with begin-bridge-trzar-io.pages.dev or any links associated with it, as it is confirmed to be actively engaged in cryptocurrency theft. To verify the safety of domains before use, PhishDestroy recommends utilizing its real-time threat database. If exposure has occurred, disconnect wallets immediately, revoke any unauthorized permissions, and report the incident to your platform’s fraud team. Security teams should monitor for connections to 172.66.47.11 and flag any associated transactions as high-risk. This campaign demonstrates the evolving tactics of cryptocurrency-focused threat actors, who increasingly use legitimate platforms like Cloudflare Pages to host malicious pages with minimal detection overhead. Active vigilance and automated verification tools remain critical in countering such threats.
Data Coverage
Informazioni sulla sicurezza di rete
Pipeline di risposta alle minacce
Copertura delle blocklist
10 fonti esterne monitorate · snapshot del 12/08/2026
10 fonti esterne monitorate Nessuna corrispondenza
Analisi di VirusTotal
Analisi delle prestazioni del sito
Google PageSpeed Insights — mobile performance audit of begin-bridge-trzar-io.pages.dev · checked Apr 12, 2026
Questo sito ti ha influenzato in qualche modo?
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.
Verifica qualsiasi dominio
Analisi delle minacce utilizzando blocklist archiviate, WHOIS, DNS e prove di scansione pubblica
Scansiona oraSegnala un tentativo di phishing
Segnala i domini sospetti al nostro database delle minacce — proteggi la comunità
SegnalaFeed in tempo reale sulle minacce
Segnalazioni recenti di phishing e modifiche osservate della disponibilità
MonitoraRimani informato, rimani al sicuro
Controlla le minacce in tempo reale oppure contesta questa segnalazione se ritieni che si tratti di un falso positivo