doc-trezr-help[.]pages[.]dev
“Trezor Suite® | Starting Up Your Device | Trezor®”
Сохранённое наблюдение
Зафиксированное различие заголовков
Сводка доказательств
This domain is flagged for elevated-risk brand impersonation targeting Trezor, a cryptocurrency hardware wallet provider. Analysis indicates the infrastructure is designed to mimic the Trezor Suite interface, specifically the device initialization process, as evidenced by the page title "Trezor Suite® | Starting Up Your Device | Trezor®". Such impersonation is commonly associated with crypto drainer schemes, where victims are tricked into entering recovery phrases or private keys, leading to unauthorized fund transfers. Infrastructure analysis reveals the domain doc-trezr-help.pages.dev was registered through Cloudflare, Inc. on April 30, 2026, an anomalous future date suggesting potential manipulation of registration records. The domain resolves to IP address 188.114.96.3 and employs technologies including HSTS, Cloudflare CDN, and HTTP/3. Security vendor detections on VirusTotal stand at 10/95, while Gridinsoft assigns a trust score of 0/100. The domain appears on one security blocklist and was actively blocked by PhishDestroy. The SSL certificate is issued by Google Trust Services, a common feature in both legitimate and malicious Cloudflare-hosted pages. Mitigation requires immediate action from cryptocurrency users and security teams. Users who interacted with this domain should assume compromise of any recovery phrases or private keys entered. Affected individuals must transfer remaining funds to a new wallet using an uncontaminated device and monitor all linked accounts for unauthorized transactions. Security teams should update blocklists to include the domain and its resolving IP (188.114.96.3), while Trezor users should verify they are accessing the official suite.trezor.io domain. Organizations should conduct retrospective log analysis for connections to doc-trezr-help.pages.dev or the associated IP to identify potential breaches. Given the crypto drainer threat model, emphasis should be placed on user education regarding recovery phrase security and the risks of interacting with unofficial wallet interfaces.
Data Coverage
Данные сетевой безопасности
Процесс реагирования на угрозы
Проверка по блок-листам
10 внешних источников под наблюдением · снимок от 11.08.2026
10 внешних источников под наблюдением Совпадений нет
Хронология обнаружения
-
VirusTotal
0 → 10
Технологии
Выявлено 3 технологии с высокой уверенностью
Анализ VirusTotal
Анализ производительности сайта
Google PageSpeed Insights — mobile performance audit of doc-trezr-help.pages.dev · checked Jun 26, 2026
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание