trezor-bridge-get[.]typedream[.]app
“Trezor @Login – The Official Wallet | Trezor®”
trezor-bridge-get.typedream.app — Прикритий · доступний. Уособлення бренду: Trezor; Тип шахрайства: Crypto Drainer. Зведення доказів: VirusTotal 8/91 (ChainPatrol, alphaMountain.ai, BitDefender, CyRadar, ESET); URLScan malicious verdict; 2 external blocklist matches (MetaMask, SEAL); CF Radar malicious; cloaking observed; PhishDestroy score 100/100. Реєстратор: Typedream.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
The domain trezor-bridge-get.typedream.app has been identified as an active crypto drainer threat, employing brand impersonation tactics targeting users of a well-known hardware wallet. The page prominently displays a title matching the official branding, aiming to mislead users into submitting sensitive authentication details. While there is no direct evidence of a specific drainer kit in use, the overall design and naming conventions are consistent with previous credential harvesting campaigns linked to digital asset theft.
Technical analysis provides several key indicators. The domain is registered via the Typedream platform, a service sometimes leveraged for rapid deployment of fraudulent content. VirusTotal currently reports 0 out of 95 detection engines flagging this domain, indicating a lack of widespread recognition by automated scanners. The domain resolves to IP address 188.114.97.3. As of this analysis, there is no data on the creation date, and no global blocklist or Google Safe Browsing flags have been reported against this asset. The combination of a legitimate-looking title and zero detections increases the likelihood of successful user deception during the initial phase of the campaign.
The domain remains active at the time of investigation, presenting an ongoing risk of credential and asset compromise for unsuspecting users. No public remediation or takedown actions have been observed. Given the zero detection rate and recent deployment, manual reporting to registrars and threat intelligence services is warranted. Users are advised to avoid engaging with this domain, and to verify all authentication prompts against official sources. Organizations monitoring for brand abuse should add this indicator to threat watchlists and inform at-risk user populations accordingly.
Розвіддані з мережевої безпеки
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Технології · 11 identified
Node.js is an open-source, cross-platform, JavaScript runtime environment that executes JavaScript code outside a web browser.
nodejs.org 100% впевненостіReact is an open-source JavaScript library for building user interfaces or UI components.
reactjs.org 100% впевненостіNext.js is a React framework for developing single page Javascript applications.
nextjs.org 100% впевненостіGoogle Cloud Trace is a distributed tracing system that collects latency data from applications and displays it in the Google Cloud Console.
cloud.google.com 100% впевненостіCloud CDN uses Google's global edge network to serve content closer to users.
cloud.google.com 100% впевненостіCloudflare Browser Insights is a tool that measures the performance of websites from the perspective of users.
www.cloudflare.com 100% впевненостіCloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100% впевненостіHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% впевненостіАналіз VirusTotal
Архівні докази
Аналіз конфігурації сайту
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога