login-trzr-com[.]pages[.]dev
“Trezor Login | Secure Access to Your Wallet”
Osservazione memorizzata
Contrasto dei titoli osservato
Riepilogo delle prove
PhishDestroy has flagged login-trzr-com.pages.dev as a confirmed brand impersonation phishing site targeting Trezor users, with a risk level currently under investigation but strongly indicative of malicious intent. The domain was created on March 30, 2026, and is registered through Cloudflare, Inc., resolving to IP 188.114.96.3. VirusTotal shows 0 detections out of 95 engines, indicating it has not yet been widely flagged, but the site already appears on 1 security blocklist. The page title, "Trezor Login | Secure Access to Your Wallet," is a clear attempt to steal credentials from cryptocurrency wallet holders by mimicking the legitimate Trezor login interface. Although the site is currently offline, its SSL certificate from Google Trust Services (WE1) and Cloudflare hosting suggest sophisticated countermeasures to evade detection.
Technical analysis reveals that the domain uses Cloudflare's reverse proxy to obscure the true origin server, a common tactic among phishing operators. The domain's creation date of March 30, 2026, combined with its rapid takedown, suggests a short-lived campaign aimed at harvesting credentials before being shut down. The inclusion of "pages.dev" in the domain name is a known pattern for phishing sites leveraging Cloudflare Pages for free hosting. Despite the low detection rate on VirusTotal, the site's presence on a security blocklist and its clear brand impersonation warrant immediate concern for Trezor users who may have encountered it.
To mitigate the risk, Trezor users should never enter their recovery seed or login credentials on any site that does not use the official Trezor domain (trezor.io). Enable two-factor authentication on your Trezor account and monitor for unauthorized access. If you have already entered credentials on this phishing site, immediately transfer your funds to a new wallet generated by the official Trezor Suite software and reset your recovery seed. Report any suspicious domains to Trezor's security team and consider using a hardware wallet with passphrase features for added security. PhishDestroy recommends regular scanning of your digital footprint for signs of compromised accounts and staying informed about common phishing tactics targeting cryptocurrency users.
Data Coverage
Pipeline di risposta alle minacce
Copertura delle blocklist
10 fonti esterne monitorate · snapshot del 11/08/2026
10 fonti esterne monitorate Nessuna corrispondenza
Cronologia del rilevamento
-
Cloudflare Radar
Scansione Cloudflare Radar archiviata · Apri scansione
Analisi dei domini
Dettagli tecniciDNS, nomi TLS e date
Analisi di VirusTotal
Questo sito ti ha influenzato in qualche modo?
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.
Verifica qualsiasi dominio
Analisi delle minacce utilizzando blocklist archiviate, WHOIS, DNS e prove di scansione pubblica
Scansiona oraSegnala un tentativo di phishing
Segnala i domini sospetti al nostro database delle minacce — proteggi la comunità
SegnalaFeed in tempo reale sulle minacce
Segnalazioni recenti di phishing e modifiche osservate della disponibilità
MonitoraRimani informato, rimani al sicuro
Controlla le minacce in tempo reale oppure contesta questa segnalazione se ritieni che si tratti di un falso positivo