d2295db6[.]connwa[.]pages[.]dev
“Trezor Suite”
Збережене спостереження
Зафіксована відмінність заголовків
Зведення доказів
Analysis indicates that the domain d2295db6.connwa.pages.dev was registered on February 21 2026 through Cloudflare, Inc. The domain resolves to IP address 188.114.96.3, which belongs to AS13335 Cloudflare, Inc. and is geolocated in the United States. HTTP requests return a 403 status code, and the site presents a valid SSL certificate issued by Google Trust Services under the WE1 name, with HSTS and HTTP/3 enabled, confirming the use of Cloudflare’s edge services. The page title observed in the limited snapshot is “Trezor Suite”, and the threat intelligence tags the site as impersonating the Trezor brand, specifically targeting wallet or seed credentials. Google Safe Browsing has flagged the domain for social engineering, and a Gridinsoft trust score of 0 out of 100 reflects an extremely low reputation.
VirusTotal analysis shows that 15 of 93 security vendors have marked the domain as malicious, and the domain appears on one external security blocklist. The site has been taken offline and is currently blocked by the PhishDestroy mitigation service. While the HTTP 403 response limits visible content, the combination of brand‑specific page title, Cloudflare‑based hosting, and the malicious detection profile suggests a deliberate attempt to lure Trezor users into disclosing wallet seeds.
No additional infrastructure such as command‑and‑control servers, phishing form URLs, or content delivery networks beyond Cloudflare has been observed, leaving the full payload delivery chain uncertain. Defenders should continue to monitor the domain for any re‑activation, enforce blocklists that include this host, and add the domain to internal URL filtering rules. Users of Trezor products should be warned that any unsolicited request to a site claiming to be “Trezor Suite” hosted on a cloud‑fronted domain is likely fraudulent, and they should be directed to the official Trezor website for any seed or wallet operations.
Data Coverage
Розвіддані з мережевої безпеки
Процес реагування на загрози Pipeline
Перевірка за блок-листами
10 зовнішніх джерел під наглядом · знімок від 12.08.2026
Хронологія виявлення
-
Cloudflare Radar
Сканування Cloudflare Radar збережено · Відкрити сканування
-
Статус домену
Доступний → Недоступний
Криміналістичні дані
Аналіз VirusTotal
Аналіз продуктивності сайту
Google PageSpeed Insights — mobile performance audit of d2295db6.connwa.pages.dev · checked Apr 13, 2026
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога