trezzor-eng-brdge[.]pages[.]dev
“Trezor® Bridge Guide | Secure Connection for Your Hardware”
証拠の概要
PhishDestroy identifies trezzor-eng-brdge.pages.dev as a live phishing domain masquerading as the legitimate Trezor Bridge service, a tool used by cryptocurrency hardware wallet users to facilitate secure transactions. The threat type is a cryptocurrency drainer kit deployment, specifically targeting Trezor users with a spoofed interface designed to harvest private keys, seed phrases, and other sensitive wallet data. The domain utilizes a visually similar naming convention ('trezzor' vs. 'trezor') and is hosted under Cloudflare Pages, leveraging the Pages.dev subdomain to appear innocuous while hosting malicious content. No legitimate software distribution or security service operates from this domain, and the interface is falsified to prompt users for wallet credentials under the guise of a 'bridge' update or security verification. This domain exhibits several technical indicators that warrant further inspection. VirusTotal currently reports a detection score of 1/95, indicating no active signatures have been updated to flag this domain as malicious at the time of analysis. The domain resolves to IP address 188.114.96.3, which is associated with Cloudflare’s infrastructure and is consistent with phishing pages hosted on Cloudflare Pages. The SSL certificate is issued by Google Trust Services, a common practice among both legitimate and malicious domains to avoid browser warnings about insecure connections. The domain was registered through Cloudflare, Inc., though the exact creation date is not publicly available due to Cloudflare’s privacy protections. Google Safe Browsing (GSB) has not yet blacklisted this domain, and the total number of blocklist entries remains at zero, reflecting its recent emergence in the threat landscape. The absence of detections and blocklist entries suggests this campaign is either newly launched or employs evasion techniques to delay detection. The current status of trezzor-eng-brdge.pages.dev is active and under active threat investigation as of the latest forensic analysis. Security researchers should treat this domain with high suspicion due to its intent to deceive and its current lack of detection signatures. Immediate response actions include updating threat intelligence feeds to include this domain and blocking both the domain and IP address at the network perimeter. Users are advised to avoid interacting with this domain entirely, verify any Trezor-related updates directly through the official website (trezor.io), and use hardware wallet verification tools that do not rely on web interfaces. The remaining risk is elevated due to the domain’s low detection score and the high potential for credential harvesting among unsuspecting Trezor users. This campaign highlights the sophisticated nature of cryptocurrency phishing attacks, where threat actors exploit trust in well-known brands to rapidly deploy drainer kits before detection systems catch up.
Data Coverage
ネットワークセキュリティインテリジェンス
脅威対応 Pipeline
ブロックリストの確認範囲
監視対象の外部情報源 10 件 · 保存スナップショット 2026年8月13日
コミュニティ報告
コミュニティの 1 人が報告・初回確認 2026年4月12日
- 保存済み報告
- 1
- 報告された固有 URL
- 1
コミュニティ情報
コミュニティ報告:1 件
カテゴリPHISHING
The PhishFort Detection System has flagged this as a domain threat, classified as phishing. Associated tags: subdomain, typosquat. Threat detected at 2026-05-01T07:28:13.386Z.
VirusTotalによる分析
サイトパフォーマンス分析
Google PageSpeed Insights — mobile performance audit of trezzor-eng-brdge.pages.dev · checked Apr 13, 2026
類似ドメイン
保存された類似ドメイン:74 件
すべて表示(62)
このサイトによって何か影響を受けましたか?
アカウント資格情報、個人情報、支払い情報を入力した場合、またはこのドメインからファイルをダウンロードした場合は、すぐに対処してください。インシデントを報告し、自分自身を守るのに役立つリソースを以下に示します。
お住まいの地域の当局へ報告してください
サイバー犯罪の公式連絡先 または 苦情草稿を作成する → を取得するには、国を選択してください。
任意のドメインを確認する
保存されたブロックリスト、WHOIS、DNS、および公開スキャン証拠を使用した脅威分析
今すぐスキャンフィッシングを報告する
不審なドメインを当社の脅威データベースに報告してください — コミュニティを守りましょう
レポートリアルタイム脅威情報フィード
最近のフィッシングレポートと観察された可用性の変化
監視最新情報を入手し、安全を確保しましょう
リアルタイムの脅威を監視するか、誤検知だと思われる場合はこのリストに異議を申し立ててください