trezzor-eng-brdge[.]pages[.]dev
“Trezor® Bridge Guide | Secure Connection for Your Hardware”
Osservazione memorizzata
Contrasto dei titoli osservato
Riepilogo delle prove
PhishDestroy identifies trezzor-eng-brdge.pages.dev as a live phishing domain masquerading as the legitimate Trezor Bridge service, a tool used by cryptocurrency hardware wallet users to facilitate secure transactions. The threat type is a cryptocurrency drainer kit deployment, specifically targeting Trezor users with a spoofed interface designed to harvest private keys, seed phrases, and other sensitive wallet data. The domain utilizes a visually similar naming convention ('trezzor' vs. 'trezor') and is hosted under Cloudflare Pages, leveraging the Pages.dev subdomain to appear innocuous while hosting malicious content. No legitimate software distribution or security service operates from this domain, and the interface is falsified to prompt users for wallet credentials under the guise of a 'bridge' update or security verification. This domain exhibits several technical indicators that warrant further inspection. VirusTotal currently reports a detection score of 1/95, indicating no active signatures have been updated to flag this domain as malicious at the time of analysis. The domain resolves to IP address 188.114.96.3, which is associated with Cloudflare’s infrastructure and is consistent with phishing pages hosted on Cloudflare Pages. The SSL certificate is issued by Google Trust Services, a common practice among both legitimate and malicious domains to avoid browser warnings about insecure connections. The domain was registered through Cloudflare, Inc., though the exact creation date is not publicly available due to Cloudflare’s privacy protections. Google Safe Browsing (GSB) has not yet blacklisted this domain, and the total number of blocklist entries remains at zero, reflecting its recent emergence in the threat landscape. The absence of detections and blocklist entries suggests this campaign is either newly launched or employs evasion techniques to delay detection. The current status of trezzor-eng-brdge.pages.dev is active and under active threat investigation as of the latest forensic analysis. Security researchers should treat this domain with high suspicion due to its intent to deceive and its current lack of detection signatures. Immediate response actions include updating threat intelligence feeds to include this domain and blocking both the domain and IP address at the network perimeter. Users are advised to avoid interacting with this domain entirely, verify any Trezor-related updates directly through the official website (trezor.io), and use hardware wallet verification tools that do not rely on web interfaces. The remaining risk is elevated due to the domain’s low detection score and the high potential for credential harvesting among unsuspecting Trezor users. This campaign highlights the sophisticated nature of cryptocurrency phishing attacks, where threat actors exploit trust in well-known brands to rapidly deploy drainer kits before detection systems catch up.
Data Coverage
Informazioni sulla sicurezza di rete
Pipeline di risposta alle minacce
Copertura delle blocklist
10 fonti esterne monitorate · snapshot del 12/08/2026
10 fonti esterne monitorate Nessuna corrispondenza
Analisi di VirusTotal
Analisi delle prestazioni del sito
Google PageSpeed Insights — mobile performance audit of trezzor-eng-brdge.pages.dev · checked Apr 13, 2026
Questo sito ti ha influenzato in qualche modo?
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.
Verifica qualsiasi dominio
Analisi delle minacce utilizzando blocklist archiviate, WHOIS, DNS e prove di scansione pubblica
Scansiona oraSegnala un tentativo di phishing
Segnala i domini sospetti al nostro database delle minacce — proteggi la comunità
SegnalaFeed in tempo reale sulle minacce
Segnalazioni recenti di phishing e modifiche osservate della disponibilità
MonitoraRimani informato, rimani al sicuro
Controlla le minacce in tempo reale oppure contesta questa segnalazione se ritieni che si tratti di un falso positivo