54d56f18[.]source-40r[.]pages[.]dev
“Trezor Suite”
Сохранённое наблюдение
Зафиксированное различие заголовков
Сводка доказательств
This domain, 54d56f18.source-40r.pages.dev, poses a significant threat as a brand impersonation site targeting users of Trezor, a well-known cryptocurrency hardware wallet. The site presents itself as the official Trezor Suite, a software interface for managing cryptocurrency assets. Visitors are likely to be deceived into entering sensitive credentials, such as recovery phrases or private keys, under the false pretense of accessing their wallet. Once obtained, these credentials can be used by malicious actors to drain cryptocurrency funds from victims' wallets, leading to irreversible financial loss. The page title explicitly mimics the legitimate Trezor Suite, further enhancing its deceptive appearance and increasing the likelihood of successful exploitation. Analysis indicates that this domain is part of a sophisticated phishing infrastructure. The domain was created on September 02, 2020, and is registered through Cloudflare, Inc., a common registrar for both legitimate and malicious sites. It resolves to the IP address 188.114.97.3, which is associated with Cloudflare's network (AS13335). The SSL certificate is issued by Google Trust Services, providing a false sense of security to visitors. Detection metrics reveal that 11 out of 95 security vendors on VirusTotal have flagged this domain as malicious. Additionally, the domain appears on one security blocklist, and Google Safe Browsing has classified it as a phishing site. These technical indicators collectively confirm the domain's malicious intent and high-risk nature. If a user has visited 54d56f18.source-40r.pages.dev or interacted with its content, immediate action is required to mitigate potential damage. First, disconnect the device used to access the site from any network to prevent further data exfiltration. Next, assume that any credentials or recovery phrases entered on the site have been compromised. Users should immediately transfer any remaining cryptocurrency assets from the affected wallet to a new, secure wallet with a fresh recovery phrase. It is critical to avoid reusing old credentials or recovery phrases. Additionally, monitor all linked accounts for unauthorized transactions and consider reporting the incident to relevant cybersecurity authorities or the targeted brand's official security team. Finally, scan the device for malware using updated security tools to ensure no additional threats were introduced during the visit.
Data Coverage
Процесс реагирования на угрозы
Проверка по блок-листам
10 внешних источников под наблюдением · снимок от 11.08.2026
10 внешних источников под наблюдением Совпадений нет
Хронология обнаружения
-
Статус домена
Доступен → Недоступен
-
Cloudflare Radar
Сканирование Cloudflare Radar сохранено · Открыть сканирование
-
Cloudflare Radar
Сканирование Cloudflare Radar сохранено · Открыть сканирование
Анализ VirusTotal
Анализ производительности сайта
Google PageSpeed Insights — mobile performance audit of 54d56f18.source-40r.pages.dev · checked Apr 25, 2026
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание