tresswallet[.]webflow[.]io
“Trezor Model T | The Most Advanced Hardware Wallet”
tresswallet.webflow.io — Conteúdo indisponível. Representação da marca: Trezor; Tipo de golpe: Crypto Drainer. Resumo das evidências: VirusTotal 14/91 (ChainPatrol, BitDefender, CyRadar, ESET, Emsisoft); URLScan malicious verdict; 2 external blocklist matches (MetaMask, SEAL); CF Radar malicious; PhishDestroy score 92/100. Registrador: MarkMonitor.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
This domain, tresswallet.webflow.io, operates as a crypto drainer, a specialized form of phishing infrastructure designed to exploit wallet connections on decentralized platforms. Analysis indicates the domain deploys malicious JavaScript to intercept and drain cryptocurrency assets from connected wallets, typically by tricking users into signing transactions that transfer funds to attacker-controlled addresses. The threat is particularly severe due to its direct financial impact, often resulting in irreversible asset loss for victims. Evidence supporting this assessment includes detection by 17 out of 95 security vendors on VirusTotal, indicating a broad consensus on its malicious nature. The domain was registered through MarkMonitor, Inc. on May 08, 2013, though its current malicious use suggests compromise or repurposing of existing infrastructure. It appears on four independent security blocklists, including those maintained by wallet security providers and domain reputation services. The domain resolves to the IP address 104.18.36.248, a Cloudflare-associated address, which is commonly used to obfuscate the true origin of malicious traffic. Users who interacted with tresswallet.webflow.io should immediately revoke any wallet connections or permissions granted to the domain. All active sessions should be terminated, and any transactions signed during the interaction period should be reviewed for unauthorized transfers. It is recommended to transfer remaining assets to a new wallet address and monitor connected accounts for suspicious activity. If credentials or recovery phrases were entered, assume full compromise and initiate account recovery procedures with the respective wallet provider. No further interaction with the domain should occur, even if it appears inactive, as it may reactivate or redirect to other malicious endpoints.
Inteligência de segurança de rede
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Tecnologias · 2 identified
Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100% de confiançaHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% de confiançaAnálise do VirusTotal
Análise de desempenho do site
Google PageSpeed Insights — mobile performance audit of tresswallet.webflow.io · checked Jun 25, 2026
Evidências e relatórios externos
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo