trezzor-eng-brdge[.]pages[.]dev
“Trezor® Bridge Guide | Secure Connection for Your Hardware”
Зведення доказів
PhishDestroy identifies trezzor-eng-brdge.pages.dev as a live phishing domain masquerading as the legitimate Trezor Bridge service, a tool used by cryptocurrency hardware wallet users to facilitate secure transactions. The threat type is a cryptocurrency drainer kit deployment, specifically targeting Trezor users with a spoofed interface designed to harvest private keys, seed phrases, and other sensitive wallet data. The domain utilizes a visually similar naming convention ('trezzor' vs. 'trezor') and is hosted under Cloudflare Pages, leveraging the Pages.dev subdomain to appear innocuous while hosting malicious content. No legitimate software distribution or security service operates from this domain, and the interface is falsified to prompt users for wallet credentials under the guise of a 'bridge' update or security verification. This domain exhibits several technical indicators that warrant further inspection. VirusTotal currently reports a detection score of 1/95, indicating no active signatures have been updated to flag this domain as malicious at the time of analysis. The domain resolves to IP address 188.114.96.3, which is associated with Cloudflare’s infrastructure and is consistent with phishing pages hosted on Cloudflare Pages. The SSL certificate is issued by Google Trust Services, a common practice among both legitimate and malicious domains to avoid browser warnings about insecure connections. The domain was registered through Cloudflare, Inc., though the exact creation date is not publicly available due to Cloudflare’s privacy protections. Google Safe Browsing (GSB) has not yet blacklisted this domain, and the total number of blocklist entries remains at zero, reflecting its recent emergence in the threat landscape. The absence of detections and blocklist entries suggests this campaign is either newly launched or employs evasion techniques to delay detection. The current status of trezzor-eng-brdge.pages.dev is active and under active threat investigation as of the latest forensic analysis. Security researchers should treat this domain with high suspicion due to its intent to deceive and its current lack of detection signatures. Immediate response actions include updating threat intelligence feeds to include this domain and blocking both the domain and IP address at the network perimeter. Users are advised to avoid interacting with this domain entirely, verify any Trezor-related updates directly through the official website (trezor.io), and use hardware wallet verification tools that do not rely on web interfaces. The remaining risk is elevated due to the domain’s low detection score and the high potential for credential harvesting among unsuspecting Trezor users. This campaign highlights the sophisticated nature of cryptocurrency phishing attacks, where threat actors exploit trust in well-known brands to rapidly deploy drainer kits before detection systems catch up.
Data Coverage
Розвіддані з мережевої безпеки
Процес реагування на загрози Pipeline
Перевірка за блок-листами
10 зовнішніх джерел під наглядом · знімок від 13.08.2026
Повідомлення спільноти
Повідомив 1 учасник спільноти; уперше помічено 12.04.2026
- Збережені повідомлення
- 1
- Унікальні URL
- 1
Дані спільноти
1 повідомлення спільноти
КатегоріяPHISHING
The PhishFort Detection System has flagged this as a domain threat, classified as phishing. Associated tags: subdomain, typosquat. Threat detected at 2026-05-01T07:28:13.386Z.
Аналіз VirusTotal
Аналіз продуктивності сайту
Google PageSpeed Insights — mobile performance audit of trezzor-eng-brdge.pages.dev · checked Apr 13, 2026
Схожі домени
Збережено 74 схожі домени
Показати всі (62)
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога