trezzor-eng-brdge[.]pages[.]dev
“Trezor® Bridge Guide | Secure Connection for Your Hardware”
증거 요약
PhishDestroy identifies trezzor-eng-brdge.pages.dev as a live phishing domain masquerading as the legitimate Trezor Bridge service, a tool used by cryptocurrency hardware wallet users to facilitate secure transactions. The threat type is a cryptocurrency drainer kit deployment, specifically targeting Trezor users with a spoofed interface designed to harvest private keys, seed phrases, and other sensitive wallet data. The domain utilizes a visually similar naming convention ('trezzor' vs. 'trezor') and is hosted under Cloudflare Pages, leveraging the Pages.dev subdomain to appear innocuous while hosting malicious content. No legitimate software distribution or security service operates from this domain, and the interface is falsified to prompt users for wallet credentials under the guise of a 'bridge' update or security verification. This domain exhibits several technical indicators that warrant further inspection. VirusTotal currently reports a detection score of 1/95, indicating no active signatures have been updated to flag this domain as malicious at the time of analysis. The domain resolves to IP address 188.114.96.3, which is associated with Cloudflare’s infrastructure and is consistent with phishing pages hosted on Cloudflare Pages. The SSL certificate is issued by Google Trust Services, a common practice among both legitimate and malicious domains to avoid browser warnings about insecure connections. The domain was registered through Cloudflare, Inc., though the exact creation date is not publicly available due to Cloudflare’s privacy protections. Google Safe Browsing (GSB) has not yet blacklisted this domain, and the total number of blocklist entries remains at zero, reflecting its recent emergence in the threat landscape. The absence of detections and blocklist entries suggests this campaign is either newly launched or employs evasion techniques to delay detection. The current status of trezzor-eng-brdge.pages.dev is active and under active threat investigation as of the latest forensic analysis. Security researchers should treat this domain with high suspicion due to its intent to deceive and its current lack of detection signatures. Immediate response actions include updating threat intelligence feeds to include this domain and blocking both the domain and IP address at the network perimeter. Users are advised to avoid interacting with this domain entirely, verify any Trezor-related updates directly through the official website (trezor.io), and use hardware wallet verification tools that do not rely on web interfaces. The remaining risk is elevated due to the domain’s low detection score and the high potential for credential harvesting among unsuspecting Trezor users. This campaign highlights the sophisticated nature of cryptocurrency phishing attacks, where threat actors exploit trust in well-known brands to rapidly deploy drainer kits before detection systems catch up.
Data Coverage
네트워크 보안 인텔리전스
위협 대응 Pipeline
차단 목록 범위
모니터링 중인 외부 피드 10개 · 저장된 스냅샷 2026년 8월 13일
VirusTotal 분석
사이트 성능 분석
Google PageSpeed Insights — mobile performance audit of trezzor-eng-brdge.pages.dev · checked Apr 13, 2026
이 사이트로 인해 영향을 받으셨나요?
계정 자격 증명, 개인 정보 또는 결제 정보를 입력했거나 이 도메인에서 파일을 다운로드한 경우 즉시 조치를 취하세요. 다음은 사건을 신고하고 자신을 보호하는 데 도움이 되는 리소스입니다.
지역 당국에 신고하십시오
공식 사이버 범죄 연락처 또는 불만사항 초안 작성 →를 받으려면 국가를 선택하세요.
모든 도메인 확인
저장된 차단 목록, WHOIS, DNS 및 공개 스캔 증거를 사용한 위협 분석
지금 스캔하기피싱 신고
의심스러운 도메인을 당사의 위협 데이터베이스에 신고해 주세요 — 커뮤니티를 보호해 주세요
보고서실시간 위협 정보
최근 피싱 보고서 및 관찰된 가용성 변경 사항
모니터링