connects-suites-trze-io[.]pages[.]dev
“Trezor Suite App (Official) | Desktop”
connects-suites-trze-io.pages.dev — İçerik kullanılamıyor. Marka kimliğine bürünme: Trezor; Dolandırıcılık türü: Brand Impersonation. Kanıt özeti: VirusTotal 12/94 (ADMINUSLabs, alphaMountain.ai, BitDefender, CyRadar, ESET); URLScan malicious verdict; PhishDestroy score 91/100. Kayıt kuruluşu: Cloudflare.
Özgün adli kaydı korumak için aşağıdaki ayrıntılı PhishDestroy AI analizi İngilizce bırakılmıştır.
PhishDestroy identifies connects-suites-trze-io.pages.dev as an active credential theft phishing domain operating at an elevated risk level. This Pages.dev subdomain employs deceptive branding to mimic legitimate connectivity services, tricking users into submitting login credentials or financial information under false pretenses. The threat is classified as credential theft rather than generic phishing due to its targeted impersonation tactics and potential for immediate account compromise. This domain was flagged by 1 out of 95 VirusTotal security vendors and registered through Cloudflare, Inc. It resolves to IP address 188.114.96.3, a Google Trust Services SSL certificate. The Pages.dev infrastructure indicates a Cloudflare Workers deployment, which adversaries often abuse for fast-flux hosting to evade traditional blocklists. Despite its professional appearance through Google Trust Services, the domain has not been widely adopted by reputable security platforms, suggesting limited detection coverage. The combination of low VirusTotal coverage (1/95) and association with cloud-based hosting solutions like Pages.dev creates a high-risk profile for unsuspecting users. To mitigate credential theft risks, immediately block connects-suites-trze-io.pages.dev at the network and endpoint levels using updated threat intelligence feeds. Users who may have interacted with this domain should rotate all credentials exposed to it and enable multi-factor authentication on affected accounts. Organizations should deploy DNS filtering policies to block Pages.dev subdomains entirely, given the platform's frequent abuse by credential phishing campaigns. Monitor for lateral movement if credentials were entered, as threat actors often leverage stolen access for further exploitation. Report any suspicious activity to your security team and consider adding this domain to internal blocklists with urgency.
Ağ Güvenliği İstihbaratı
Tehdit Müdahale Pipeline
Genel Engelleme Listesi Durumu
Adli İstihbarat
Teknolojiler · 3 identified
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
VirusTotal Analizi
Site Performans Analizi
Google PageSpeed Insights — mobile performance audit of connects-suites-trze-io.pages.dev · checked Apr 1, 2026
Kanıtlar ve Dış Raporlar
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin