trezor[.]io-suite-bridge[.]app
“trezor.io-suite-bridge.app”
trezor.io-suite-bridge.app — Контент недоступен. Олицетворение бренда: Trezor; Тип мошенничества: Crypto Drainer. Сводка доказательств: VirusTotal 5/91 (Emsisoft, Fortinet, Netcraft, SOCRadar, Webroot); Spamhaus DBL_PHISH; CF Radar malicious; PhishDestroy score 65/100.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
Analysis as of July 27, 2026 indicates that the domain trezor.io-suite-bridge.app remains active and is classified as a crypto‑drainer infrastructure. The domain is currently blocked by the PhishDestroy sinkhole, suggesting that defensive operators have observed malicious traffic and taken mitigation steps. Authoritative name servers are a.dnspod.com, b.dnspod.com and c.dnspod.com, which are typical of the DNSPod service and provide no immediate indication of compromise beyond the fact that the domain resolves to a single IPv4 address, 82.27.2.25. The IP address is listed on one public security blocklist, reinforcing the view that it is associated with abusive activity.
VirusTotal has processed the domain with 91 antivirus and URL‑reputation engines; none of the engines reported a detection at the time of the scan. While the lack of detections does not confirm benign intent, it demonstrates that the domain has not yet been flagged by the majority of commercial scanners. No public Safe Browsing, Open Threat Exchange, or registrar‑level reputation data were found for the domain, and no SSL certificate details or HTTP response codes have been published. Consequently, the current evidence base is limited to DNS and blocklist information.
Defenders should continue to monitor the domain, enforce existing blocklist entries, and consider adding the domain to local deny lists. Network traffic to 82.27.2.25 should be inspected for signs of cryptocurrency transaction interception or wallet credential exfiltration, consistent with the crypto‑drainer profile. Ongoing collection of page content, TLS fingerprints, and any observed payloads will be essential to refine detection signatures and to confirm whether the infrastructure is being used to target specific cryptocurrency platforms.
Данные сетевой безопасности
Процесс реагирования на угрозы
Статус в публичных блок-листах
Сохранённый снимок
Аналитика доменов
Технические сведенияDNS, SAN в протоколе SSL, временные метки
Анализ VirusTotal
Доказательства и внешние отчеты
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание