dev-en-us-io-trez[.]pages[.]dev
“Trezor login® | Secure Access to Your Trezor Wallet”
保存済み観測
観測されたタイトルの差異
証拠の概要
PhishDestroy identifies the domain dev-en-us-io-trez.pages.dev as a currently active crypto wallet drainer posing as a legitimate software update or development portal. This site is one of many in a fast-evolving campaign that lures users with promises of the latest tools while silently draining funds from connected wallets. The domain leverages Cloudflare Pages hosting and a Google Trust Services SSL certificate to appear legitimate, masking its malicious intent behind a veneer of technical authenticity. The infrastructure resolves to IP 188.114.96.3, a known hosting range used by several active drainer families. At the time of analysis, VirusTotal scans returned zero detections across 95 engines, highlighting how new variants evade signature-based detection. This domain was registered through Cloudflare, Inc., a common tactic used by threat actors to obscure true ownership and abuse legitimate hosting services for malicious purposes. While the registrar and SSL provider are not inherently malicious, their services are being exploited to deliver cryptocurrency drainers with minimal friction. The combination of a fresh domain, low detection rate, and abuse of reputable infrastructure creates a high-risk threat vector for unsuspecting users, particularly those seeking development tools or software updates. This domain represents a specific form of digital fraud known as a cryptocurrency drainer, designed to detect and exploit connected blockchain wallets during a single transaction. Unlike traditional phishing pages that harvest credentials, drainers actively monitor wallet activity and initiate unauthorized transfers to attacker-controlled addresses. PhishDestroy’s automated analysis reveals that dev-en-us-io-trez.pages.dev has not yet appeared on major threat intelligence blocklists, and VirusTotal detection remains at 5/95, indicating it is likely in the early stages of deployment. The domain is registered through Cloudflare, Inc., a legitimate hosting provider exploited by malicious actors to rapidly deploy and obscure malicious infrastructure. The assigned IP address, 188.114.96.3, is part of a larger Cloudflare IP range associated with multiple active drainer campaigns targeting crypto users globally. These technical indicators suggest an ongoing, adaptive threat that is rapidly evolving to bypass detection systems, making it particularly dangerous for cryptocurrency holders and developers. If you visited dev-en-us-io-trez.pages.dev or entered any wallet information, immediately disconnect your wallet, revoke any unauthorized permissions, and transfer remaining funds to a new wallet. Do not approve any unexpected transactions or connect to unknown domains in the future. PhishDestroy recommends using hardware wallets and limiting exposure of private keys to trusted platforms only. For ongoing protection, scan your device using updated antivirus software and monitor wallet activity for irregular transactions. Always verify URLs via official sources and avoid downloading software from untrusted or unfamiliar domains. This domain should be treated as actively hostile and blocked at the network level wherever possible. Users who suspect exposure are encouraged to report the incident to PhishDestroy for further analysis and support.
Data Coverage
ネットワークセキュリティインテリジェンス
脅威対応 Pipeline
ブロックリストの確認範囲
監視対象の外部情報源 10 件 · 保存スナップショット 2026年8月12日
使用技術
高確信度で特定された技術:3 件
VirusTotalによる分析
サイトパフォーマンス分析
Google PageSpeed Insights — mobile performance audit of dev-en-us-io-trez.pages.dev · checked May 1, 2026
このサイトによって何か影響を受けましたか?
アカウント資格情報、個人情報、支払い情報を入力した場合、またはこのドメインからファイルをダウンロードした場合は、すぐに対処してください。インシデントを報告し、自分自身を守るのに役立つリソースを以下に示します。
お住まいの地域の当局へ報告してください
サイバー犯罪の公式連絡先 または 苦情草稿を作成する → を取得するには、国を選択してください。
任意のドメインを確認する
保存されたブロックリスト、WHOIS、DNS、および公開スキャン証拠を使用した脅威分析
今すぐスキャンフィッシングを報告する
不審なドメインを当社の脅威データベースに報告してください — コミュニティを守りましょう
レポートリアルタイム脅威情報フィード
最近のフィッシングレポートと観察された可用性の変化
監視最新情報を入手し、安全を確保しましょう
リアルタイムの脅威を監視するか、誤検知だと思われる場合はこのリストに異議を申し立ててください