trezor[.]io-suite-bridge[.]app
“trezor.io-suite-bridge.app”
trezor.io-suite-bridge.app — Conteúdo indisponível. Representação da marca: Trezor; Tipo de golpe: Crypto Drainer. Resumo das evidências: VirusTotal 5/91 (Emsisoft, Fortinet, Netcraft, SOCRadar, Webroot); Spamhaus DBL_PHISH; CF Radar malicious; PhishDestroy score 65/100.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
Analysis as of July 27, 2026 indicates that the domain trezor.io-suite-bridge.app remains active and is classified as a crypto‑drainer infrastructure. The domain is currently blocked by the PhishDestroy sinkhole, suggesting that defensive operators have observed malicious traffic and taken mitigation steps. Authoritative name servers are a.dnspod.com, b.dnspod.com and c.dnspod.com, which are typical of the DNSPod service and provide no immediate indication of compromise beyond the fact that the domain resolves to a single IPv4 address, 82.27.2.25. The IP address is listed on one public security blocklist, reinforcing the view that it is associated with abusive activity.
VirusTotal has processed the domain with 91 antivirus and URL‑reputation engines; none of the engines reported a detection at the time of the scan. While the lack of detections does not confirm benign intent, it demonstrates that the domain has not yet been flagged by the majority of commercial scanners. No public Safe Browsing, Open Threat Exchange, or registrar‑level reputation data were found for the domain, and no SSL certificate details or HTTP response codes have been published. Consequently, the current evidence base is limited to DNS and blocklist information.
Defenders should continue to monitor the domain, enforce existing blocklist entries, and consider adding the domain to local deny lists. Network traffic to 82.27.2.25 should be inspected for signs of cryptocurrency transaction interception or wallet credential exfiltration, consistent with the crypto‑drainer profile. Ongoing collection of page content, TLS fingerprints, and any observed payloads will be essential to refine detection signatures and to confirm whether the infrastructure is being used to target specific cryptocurrency platforms.
Inteligência de segurança de rede
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Captura armazenada
Inteligência de Domínios
Detalhes técnicosDNS, SANs do SSL, carimbos de data e hora
Análise do VirusTotal
Evidências e relatórios externos
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo