begin-bridge-8uj[.]pages[.]dev
“Trezor Bridge | Secure Connection for Trezor Devices”
Observação armazenada
Contraste de títulos observado
Resumo das evidências
PhishDestroy identifies begin-bridge-8uj.pages.dev as a domain currently under investigation for potential involvement in cryptocurrency drainer operations. The threat type is specifically a crypto drainer phishing campaign, designed to trick users into connecting their crypto wallets and unknowingly approve malicious transactions that drain funds. Given the active status and low detection rates, this domain poses a significant risk to unsuspecting cryptocurrency users, particularly those engaging with decentralized applications or platforms associated with cloud-based hosting services like Cloudflare Pages. This domain resolves to IP address 172.66.44.111 and operates under a Cloudflare, Inc. registrar, utilizing Google Trust Services for its SSL certificate. VirusTotal currently flags this domain with a 3 out of 95 detection score, indicating it has not yet been widely recognized by security vendors as malicious. The domain is hosted on Cloudflare Pages, a legitimate service, which may be leveraged to obfuscate its true intent. The risk level remains classified as under_investigation, but the absence of detections and active status warrant heightened scrutiny. No additional blocklists or reputation scores were provided in the available intelligence at this time. Analysts should treat begin-bridge-8uj.pages.dev as a high-risk crypto drainer domain and prioritize mitigation efforts accordingly. Users are advised to avoid interacting with this domain, particularly any prompts to connect crypto wallets or approve transactions. Security teams should monitor network traffic for connections to IP 172.66.44.111 and inspect SSL certificates associated with Google Trust Services for anomalous domains. Implementing network-level blocking for this domain and IP address is recommended until further intelligence confirms its legitimacy or malicious nature. Additionally, users should enable wallet transaction approval alerts and verify the authenticity of any platform prompting for crypto wallet connections through out-of-band communication channels.
Data Coverage
Inteligência de segurança de rede
Pipeline de resposta a ameaças
Cobertura de listas de bloqueio
10 fontes externas monitoradas · instantâneo de 12/08/2026
10 fontes externas monitoradas Sem correspondência
Inteligência forense
Análise do VirusTotal
Análise de desempenho do site
Google PageSpeed Insights — mobile performance audit of begin-bridge-8uj.pages.dev · checked Mar 25, 2026
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo