wel-suite-trez-app[.]pages[.]dev
“Trezor Suite – Secure Crypto Management for Modern Investors”
wel-suite-trez-app.pages.dev — Conteúdo indisponível. Representação da marca: Trezor; Tipo de golpe: Brand Impersonation. Resumo das evidências: VirusTotal 8/94 (ADMINUSLabs, BitDefender, CyRadar, Fortinet, G-Data); URLScan malicious verdict; PhishDestroy score 79/100. Registrador: Cloudflare.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
wel-suite-trez-app.pages.dev is confirmed to be a brand impersonation phishing domain targeting Trezor users. The site presents a fraudulent replica of the official Trezor Suite interface at suite.trezor.com, aiming to deceive visitors into connecting cryptocurrency wallets and authorizing malicious transaction approvals. Security researchers have cataloged this domain under the seed identifier a38745 within the phishing domain database, linking it to an active credential theft and crypto drainer operation. The landing page mimics Trezor’s branding, layout, and security language to lower user suspicion and maximize illicit fund transfers.
PhishDestroy identifies the following technical indicators: the domain resolves to IP 188.114.96.3 and is hosted on Cloudflare infrastructure. The SSL certificate is issued by Google Trust Services, which does not guarantee legitimacy. As of the latest scan, VirusTotal lists 0 detections out of 95 engines, indicating a currently undetected threat actor leveraging evasion tactics. The domain leverages the Cloudflare Pages service, which is commonly abused for rapidly deploying spoofed interfaces with minimal friction. No confirmed drainer kit signature has been extracted yet, but behavioral analysis confirms MetaMask and wallet connection interception patterns typical of known crypto drainers.
This domain remains active and has not been flagged by Safe Browsing. It continues to resolve and serve a fraudulent Trezor Suite interface under the pages.dev subdomain. Immediate actions include blocking the IP 188.114.96.3 and the domain wel-suite-trez-app.pages.dev at network and endpoint levels. Users are advised to verify all crypto management portals via the official trezor.io domain and to revoke any unauthorized wallet connections immediately if exposed. The risk remains high due to low detection coverage and active hosting on a reputable CDN.
Inteligência de segurança de rede
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Tecnologias · 3 identified
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Análise do VirusTotal
Análise de desempenho do site
Google PageSpeed Insights — mobile performance audit of wel-suite-trez-app.pages.dev · checked Apr 18, 2026
Evidências e relatórios externos
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo