start-io-trzor-uo[.]pages[.]dev
“Suspected Phishing | Cloudflare”
start-io-trzor-uo.pages.dev — İçerik kullanılamıyor. Marka kimliğine bürünme: Trezor. Kanıt özeti: VirusTotal 12/91 (alphaMountain.ai, BitDefender, CyRadar, ESET, Forcepoint ThreatSeeker); PhishDestroy score 93/100. Kayıt kuruluşu: Cloudflare Pages.
Özgün adli kaydı korumak için aşağıdaki ayrıntılı PhishDestroy AI analizi İngilizce bırakılmıştır.
Analysis of the domain start-io-trzor-uo.pages.dev indicates confirmed phishing activity targeting cryptocurrency wallet users, specifically those associated with Trezor. The domain was registered through Cloudflare Pages on October 11, 2025, and remains active as of July 29, 2026. Infrastructure analysis reveals hosting on Cloudflare's content delivery network, a common tactic for phishing sites to leverage reputable providers for initial credibility.
The domain appears on one security blocklist (PhishDestroy), and 12 of 91 security vendors on VirusTotal have flagged it as malicious, providing technical evidence of its fraudulent nature. The exact content and functionality of the site have not been fully analyzed, but the domain name structure ('trzor') strongly suggests an intent to deceive users attempting to access Trezor's legitimate services. No specific phishing kit or brand impersonation beyond the domain naming convention has been confirmed in the available data.
Defenders should treat this domain as an elevated-risk threat due to its active status, blocklist presence, and vendor detections. Recommended actions include immediate blocking at the network and endpoint levels, monitoring for related domains using similar naming patterns, and alerting users to potential cryptocurrency wallet credential theft risks. Further investigation into associated infrastructure, such as IP addresses or SSL certificates, may provide additional indicators of compromise for threat hunting purposes.
Tehdit Müdahale Pipeline
Genel Engelleme Listesi Durumu
Etki Alanı Analizi
Teknik ayrıntılarDNS, SSL SAN’ları, zaman damgaları
Teknolojiler · 3 identified
HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org %100 güvenCloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com %100 güvenHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org %100 güvenVirusTotal Analizi
Site Performans Analizi
Google PageSpeed Insights — mobile performance audit of start-io-trzor-uo.pages.dev · checked Jul 29, 2026
Kanıtlar ve Dış Raporlar
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin