trozr-eiwuy[.]deylaa12[.]workers[.]dev
“Trezor Suite”
Kaydedilmiş gözlem
Gözlemlenen başlık farkı
Kanıt özeti
This domain, trozr-eiwuy.deylaa12.workers.dev, is flagged as a high-risk brand impersonation threat specifically targeting Trezor, a cryptocurrency hardware wallet provider. Analysis indicates the site mimics the legitimate Trezor Suite interface, a tactic commonly used in credential harvesting and cryptocurrency theft operations. No explicit drainer kit signatures were identified, but the presence of Bootstrap and jQuery suggests a structured phishing framework designed to replicate the authentic user experience. Infrastructure analysis reveals the domain was registered through Cloudflare, Inc. on April 25, 2026, resolving to the IP address 104.21.30.64. The domain is currently flagged by 12 out of 95 security vendors on VirusTotal, with detections from multiple blocklists, including MetaMask and PhishDestroy. It appears on three independent security blocklists, and its SSL certificate is issued by Google Trust Services. Technologies detected include HSTS, HTTP/3, and Cloudflare, which are often leveraged to lend an appearance of legitimacy while obscuring malicious intent. As of the latest assessment, trozr-eiwuy.deylaa12.workers.dev has been taken offline, likely in response to security community reporting and blocklist enforcement. However, residual risk remains due to the domain's recent creation date and the potential for infrastructure reuse. Users who accessed the site prior to its takedown should assume credential compromise and take immediate action, including revoking wallet authorizations, rotating passwords, and monitoring for unauthorized transactions. Organizations should update internal blocklists to prevent future access attempts and monitor for similar domains leveraging the same Cloudflare Workers subdomain pattern.
Data Coverage
Ağ Güvenliği İstihbaratı
Tehdit Müdahale Pipeline
Engelleme listesi kapsamı
10 izlenen harici kaynak · kayıtlı anlık görüntü 11.08.2026
Etki Alanı Analizi
Teknik ayrıntılarDNS, TLS adları ve zaman damgaları
Teknolojiler
5 yüksek güvenli teknoloji belirlendi
VirusTotal Analizi
Site Performans Analizi
Google PageSpeed Insights — mobile performance audit of trozr-eiwuy.deylaa12.workers.dev · checked Jun 26, 2026
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin