hub-trzr-suite[.]pages[.]dev
“Trezor Suite: Getting Started with Trezor Suite”
hub-trzr-suite.pages.dev — Raggiungibile · accesso limitato (HTTP 403). Simulazione del marchio: Trezor; Tipo di truffa: Brand Impersonation. Riepilogo delle prove: VirusTotal 13/91 (ChainPatrol, alphaMountain.ai, BitDefender, CyRadar, ESET); URLScan malicious verdict; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 90/100. Registrar: Cloudflare.
L’analisi dettagliata di PhishDestroy AI resta in inglese per preservare il rapporto forense originale.
This domain is an active brand impersonation threat designed to deceive users of Trezor, a cryptocurrency hardware wallet. The site replicates the official Trezor Suite interface, tricking visitors into entering sensitive wallet credentials or downloading malicious software. If successful, attackers can drain cryptocurrency funds from connected wallets without the user's knowledge. The threat is classified as a crypto drainer due to its direct targeting of digital assets and wallet access mechanisms. Analysis indicates the domain was registered on June 15, 2026, through Cloudflare, Inc., and is hosted on the IP address 188.114.96.3. Security vendors on VirusTotal have flagged the domain, with 5 out of 95 detecting malicious activity. The SSL certificate is issued by Google Trust Services, which does not mitigate the risk given the domain's impersonation of Trezor's branding. The site appears on three security blocklists and is actively blocked by multiple threat intelligence platforms, including PhishDestroy, MetaMask, and SEAL. If you visited hub-trzr-suite.pages.dev, immediately disconnect any connected wallets or devices from the internet. Do not enter any credentials or seed phrases. Scan your device for malware using reputable security tools. If you interacted with the site, assume your wallet credentials are compromised and transfer any remaining funds to a new, secure wallet. Monitor your accounts for unauthorized transactions and report the incident to relevant cryptocurrency security resources. Avoid reusing passwords or seed phrases across platforms to prevent further exposure.
Pipeline di risposta alle minacce
Stato della lista di blocco pubblica
Tecnologie · 4 identified
HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org Confidenza al 100%Google Analytics is a free web analytics service that tracks and reports website traffic.
google.com Confidenza al 100%Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com Confidenza al 100%HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org Confidenza al 100%Analisi di VirusTotal
Dati e relazioni esterne
Questo sito ti ha influenzato in qualche modo?
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.
Verifica qualsiasi dominio
Analisi delle minacce utilizzando blocklist archiviate, WHOIS, DNS e prove di scansione pubblica
Scansiona oraSegnala un tentativo di phishing
Segnala i domini sospetti al nostro database delle minacce — proteggi la comunità
SegnalaFeed in tempo reale sulle minacce
Segnalazioni recenti di phishing e modifiche osservate della disponibilità
MonitoraRimani informato, rimani al sicuro
Controlla le minacce in tempo reale oppure contesta questa segnalazione se ritieni che si tratti di un falso positivo