trzio-starthelp[.]pages[.]dev
“Suspected phishing site | Cloudflare”
Observação armazenada
Contraste de títulos observado
Resumo das evidências
PhishDestroy identifies trzio-starthelp.pages.dev as an active crypto drainer campaign hosted on Cloudflare Pages. The domain leverages a Google Trust Services SSL certificate to impersonate a legitimate support portal, specifically targeting cryptocurrency users by tricking victims into connecting their wallets under the guise of receiving support. The threat actor’s infrastructure is currently under investigation, but technical indicators suggest ongoing malicious operations with potential for rapid expansion to additional phishing domains or payload delivery vectors. Users who interact with this domain risk immediate loss of funds through automated token approvals and transaction signing requests.
This domain was flagged by PhishDestroy’s seed 53dacb, with threat type classified as generic_phishing and risk level under_investigation. VirusTotal currently shows 0 detections out of 95 engines, indicating evasion against signature-based detection systems. The domain resolves to IP 188.114.97.3, a Cloudflare-hosted address commonly abused for phishing due to low barrier to entry and high availability. The SSL certificate is issued by Google Trust Services, which is a legitimate authority but has been observed in multiple malicious campaigns due to weak validation or compromised issuance processes. The domain is registered through Cloudflare, Inc., leveraging Pages.dev as a subdomain for rapid deployment and obfuscation. No known blocklist entries are currently recorded, and the campaign remains active with undetermined creation date, suggesting recent deployment.
Users must avoid interacting with trzio-starthelp.pages.dev entirely. If already connected, revoke wallet permissions immediately using tools like revoke.cash or your wallet’s built-in allowance manager. Never approve unsolicited token approvals or transaction requests from this domain. Report the domain to PhishDestroy and your wallet provider. Enable hardware wallet signing for all transactions to prevent automated drainer scripts. Monitor wallet activity for unusual outbound transfers, especially to unknown addresses. Use network-level protections like DNS filtering or browser extensions that block known malicious domains. Always verify support portals by visiting official websites directly and cross-referencing contact details. Stay vigilant: crypto drainers often mimic legitimate services and exploit urgency to bypass user scrutiny.
Data Coverage
Inteligência de segurança de rede
Pipeline de resposta a ameaças
Cobertura de listas de bloqueio
10 fontes externas monitoradas · instantâneo de 11/08/2026
10 fontes externas monitoradas Sem correspondência
Inteligência forense
Análise do VirusTotal
Análise de desempenho do site
Google PageSpeed Insights — mobile performance audit of trzio-starthelp.pages.dev · checked Apr 3, 2026
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo