start-trezr--x-eng-cloud[.]pages[.]dev
“Trezor Wallet: Secure Setup & Troubleshooting”
Сводка доказательств
PhishDestroy identifies the active crypto drainer domain start-trezr--x-eng-cloud.pages.dev, currently impersonating Trezor hardware wallet services. The threat is classified under generic phishing with an under investigation risk level, indicating ongoing analysis by security researchers. This domain presents a credible risk to cryptocurrency users, particularly those interacting with hardware wallet services, as it may attempt to deceive victims into revealing private keys or transferring digital assets to attacker-controlled addresses.
This domain was flagged by 7 of 95 VirusTotal vendors as of the latest scan, indicating that signature-based detection mechanisms have not yet identified malicious payloads or infrastructure. The domain is registered through Cloudflare, Inc., leveraging Cloudflare Pages for hosting, and utilizes a Google Trust Services SSL certificate to establish a false sense of legitimacy. The domain resolves to IP address 172.66.47.109, which is part of Cloudflare’s infrastructure, further obfuscating its true origin. The seed value c0ec76 uniquely identifies this instance in the PhishDestroy database. While no blocklist counts or trust scores are publicly available for this specific domain, the absence of VirusTotal detections and the use of reputable services like Cloudflare and Google Trust Services highlight the sophistication of this threat actor in evading initial detection.
The current status of start-trezr--x-eng-cloud.pages.dev remains active, with no confirmed takedown or mitigation efforts reported at this time. Technical indicators such as the Cloudflare Pages hosting, Google Trust Services SSL certificate, and the domain’s structure (using double hyphens and a plausible-sounding subdomain) suggest an attempt to mimic legitimate Trezor cloud services. To mitigate risk, PhishDestroy recommends users avoid interacting with this domain and verify any suspicious links or services through the PhishDestroy database. Organizations and individuals should also inspect network traffic for connections to 172.66.47.109 and monitor for unauthorized cryptocurrency transactions. Additionally, enabling multi-factor authentication (MFA) for cryptocurrency wallets and using hardware wallet verification methods can reduce exposure to such threats. Security teams are advised to update threat intelligence feeds with the seed value c0ec76 to ensure continued tracking of this domain.
Data Coverage
Данные сетевой безопасности
Процесс реагирования на угрозы
Проверка по блок-листам
10 внешних источников под наблюдением · снимок от 13.08.2026
10 внешних источников под наблюдением Совпадений нет
Сообщения сообщества
Сообщил 1 участник сообщества; впервые замечено 13.04.2026
- Сохранённые сообщения
- 1
- Уникальные URL
- 1
Данные сообщества
1 сообщение сообщества
КатегорияPHISHING
The PhishFort Detection System has flagged this as a domain threat, classified as phishing. Associated tags: subdomain, typosquat. Threat detected at 2026-05-02T02:37:42.102Z.
Анализ VirusTotal
Анализ производительности сайта
Google PageSpeed Insights — mobile performance audit of start-trezr--x-eng-cloud.pages.dev · checked Apr 13, 2026
Похожие домены
Сохранено 74 похожих домена
Показать все (62)
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание