MALICIOUS — HIGH
en-suite-web[.]pages[.]dev
This domain is flagged as a high-risk brand impersonation threat targeting cryptocurrency wallet users.
- VirusTotal
- 5/91
- Blocklists
- 2 · MetaMask, SEAL
- Kullanılabilirlik
- Ulaşılabilir · erişim kısıtlı · HTTP 403
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
en-suite-web.pages.dev — Ulaşılabilir · erişim kısıtlı (HTTP 403). Marka kimliğine bürünme: Trezor; Dolandırıcılık türü: Brand Impersonation. Kanıt özeti: VirusTotal 5/91 (ADMINUSLabs, ESET, Fortinet, Kaspersky, PhishFort); URLScan malicious verdict; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 66/100. Kayıt kuruluşu: Cloudflare.
Özgün adli kaydı korumak için aşağıdaki ayrıntılı PhishDestroy AI analizi İngilizce bırakılmıştır.
Evidence Analysis
This domain is flagged as a high-risk brand impersonation threat targeting cryptocurrency wallet users. Analysis indicates the site en-suite-web.pages.dev specifically mimics Trezor Suite, a legitimate crypto wallet interface, with the intent to harvest credentials, private keys, or seed phrases from unsuspecting victims. The threat type is classified as crypto-phishing, leveraging social engineering to exploit trust in established brands within the blockchain ecosystem. Infrastructure analysis reveals the domain was registered through Cloudflare, Inc. on August 18, 2025, and resolves to the IP address 172.66.45.24. The site employed HSTS and HTTP/3 protocols, alongside a Google Trust Services SSL certificate, to present a facade of legitimacy. VirusTotal detection metrics show 15 out of 95 security vendors flagged the domain as malicious. The domain appears on three security blocklists and is actively blocked by cryptocurrency security tools, including MetaMask and PhishDestroy. The page title, 'Trezor Suite - Secure Your Crypto Wallet,' directly mirrors the legitimate service, increasing the likelihood of successful deception. Mitigation requires immediate action from both end-users and security teams. Users who accessed en-suite-web.pages.dev should assume credential compromise and revoke all active sessions on their crypto wallets. They must generate new seed phrases, transfer assets to new wallet addresses, and monitor for unauthorized transactions. Security teams should add the domain and its resolving IP (172.66.45.24) to enterprise blocklists, along with associated SSL certificate fingerprints. Network-level detection rules should be updated to flag similar Cloudflare-hosted pages impersonating crypto services. Given the domain's recent creation date, proactive threat hunting for related infrastructure (e.g., subdomains, redirect chains) is recommended to identify and neutralize secondary attack vectors.
Veri kapsamı12 recorded checks
Tehdit Müdahale Pipeline
Genel Engelleme Listesi Durumu
Teknolojiler · 3 identified
HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org %100 güvenCloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com %100 güvenHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org %100 güvenVirusTotal Analizi
Site Performans Analizi
Google PageSpeed Insights — mobile performance audit of en-suite-web.pages.dev · checked Jun 26, 2026
Kanıtlar ve Dış RaporlarIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.