tresor-welt-suite[.]pages[.]dev
“Trezor Suite - Web3 App”
tresor-welt-suite.pages.dev — Conteúdo indisponível. Representação da marca: Trezor; Tipo de golpe: Brand Impersonation. Resumo das evidências: VirusTotal 5/94 (BitDefender, CyRadar, G-Data, Kaspersky, LevelBlue); URLScan malicious verdict; PhishDestroy score 70/100. Registrador: Cloudflare.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
PhishDestroy identifies tresor-welt-suite.pages.dev as a live crypto drainer domain designed to deceive users into connecting crypto wallets under the pretext of a Trezor Suite impersonation. Registered through Cloudflare, the domain is currently active and under investigation due to its malicious intent to siphon digital assets. The threat involves the deployment of a wallet-draining script that executes unauthorized transactions upon wallet connection, resulting in immediate fund loss for unsuspecting victims. This domain resolves to IP 172.66.44.154 and operates with a SSL certificate issued by Google Trust Services. Despite zero detections out of 95 VirusTotal vendors, the domain remains unlisted on major blocklists as of this report, indicating a gap in current threat intelligence coverage. The absence of detections—paired with the domain’s active status and the use of Cloudflare’s infrastructure—highlights the sophistication of this campaign, which leverages reputable hosting and encryption to evade detection mechanisms. Trust scores provided by threat intelligence platforms remain uncalculated due to the domain’s recency and the low vendor coverage, underscoring the need for proactive monitoring. Users are strongly advised to avoid interacting with tresor-welt-suite.pages.dev and to verify the legitimacy of any Trezor Suite-related domains using PhishDestroy’s threat database. Given the domain’s active status and the specific threat of wallet draining, immediate action is recommended: avoid clicking links, disconnect any previously connected wallets, and report the domain to PhishDestroy for further analysis. Security teams should monitor network traffic for connections to this IP and investigate potential lateral movement within affected environments. Blocking the IP 172.66.44.154 at the firewall level is also advised to mitigate exposure while the domain undergoes deeper investigation.
Inteligência de segurança de rede
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Análise do VirusTotal
Análise de desempenho do site
Google PageSpeed Insights — mobile performance audit of tresor-welt-suite.pages.dev · checked Apr 10, 2026
Evidências e relatórios externos
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo