connect-bridge-trzzar[.]pages[.]dev
“Suspected Phishing | Cloudflare”
connect-bridge-trzzar.pages.dev — Conteúdo indisponível. Representação da marca: MetaMask. Resumo das evidências: VirusTotal 13/91 (ChainPatrol, Criminal IP, alphaMountain.ai, BitDefender, CyRadar); 2 external blocklist matches (MetaMask, SEAL); CF Radar malicious; PhishDestroy score 89/100. Registrador: Cloudflare Pages.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
Analysis indicates that the domain connect-bridge-trzzar.pages.dev is actively used in a high‑risk phishing campaign. The domain was registered on 7 November 2025 via the Cloudflare Pages service, which provides automated hosting and DNS management. DNS resolution points to the IPv4 address 172.66.47.163, an address associated with Cloudflare’s edge network. The domain appears on three independent security blocklists and is explicitly blocked by the PhishDestroy, MetaMask, and SEAL filtering solutions, confirming that multiple vendors have observed malicious activity originating from it.
VirusTotal reports that 13 of 91 scanned security engines have flagged the domain, reinforcing the suspicion of malicious intent. The intelligence set classifies the activity as generic phishing, and the risk level is marked as high, with the campaign status listed as active. Publicly available details such as the page title, SSL certificate metadata, or HTTP response codes have not been disclosed, leaving the exact content of the hosted page unverified. Consequently, defenders cannot confirm the specific lure or credential‑harvesting technique employed, but the convergence of blocklist listings, vendor detections, and the Cloudflare Pages hosting model strongly suggests a credential‑stealing operation.
Recommended mitigation steps include adding the domain and its resolved IP address to network allow‑lists and endpoint blocklists, enforcing DNS filtering that references the known blocklists, and monitoring for any outbound connections to 172.66.47.163. Continuous re‑scanning on VirusTotal or similar multi‑engine platforms is advised to capture any changes in detection ratios. Organizations should also educate users about the risk of unsolicited login prompts that may reference the “connect‑bridge‑trzzar” pattern, even though the exact visual presentation is not yet documented.
Inteligência de segurança de rede
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Tecnologias · 3 identified
HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 100% de confiançaCloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100% de confiançaHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% de confiançaAnálise do VirusTotal
Análise de desempenho do site
Google PageSpeed Insights — mobile performance audit of connect-bridge-trzzar.pages.dev · checked Jul 29, 2026
Evidências e relatórios externos
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo