wwv[.]suite[.]trezor[.]io[.]bridge-v5[.]app
“Google”
wwv.suite.trezor.io.bridge-v5.app — Неперевірений. Уособлення бренду: Trezor; Тип шахрайства: Crypto Drainer. Зведення доказів: VirusTotal 15/91 (alphaMountain.ai, Chong Lua Dao, CRDF, CyRadar, ESET); Spamhaus DBL_BOTNET; PhishDestroy score 95/100.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
Analysis of the domain wwv.suite.trezor.io.bridge-v5.app, registered under nameservers a.dnspod.com, b.dnspod.com, and c.dnspod.com, indicates active infrastructure supporting a crypto drainer phishing campaign as of July 29, 2026. The domain resolves to the IP address 195.96.132.157, which has not been subjected to widespread public scanning at this time, limiting visibility into broader detection metrics. Infrastructure analysis reveals the use of DNSPod nameservers, a provider frequently associated with rapidly deployed phishing domains due to its low-cost and flexible registration policies. The domain appears on at least one security blocklist, specifically PhishDestroy, which has flagged it as malicious.
No additional blocklist entries, Safe Browsing alerts, or Open Threat Exchange (OTX) pulses were identified in the available data. The absence of further detections does not imply benign status; rather, it reflects limited exposure or delayed reporting by other vendors. The domain remains active, serving as a potential vector for cryptocurrency theft by tricking users into connecting wallets to malicious smart contracts. Defenders are advised to treat this domain as high-risk and implement immediate blocking at the DNS and network levels.
Organizations should monitor for connections to 195.96.132.157 and the associated nameserver infrastructure, as these may indicate compromised endpoints or ongoing phishing activity. Given the domain's explicit targeting of cryptocurrency users—evidenced by its subdomain structure mimicking Trezor Suite—security teams should prioritize user education around wallet security and phishing red flags. Further investigation into the hosting provider and registrar is recommended to assess potential takedown avenues.
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Перехресна перевірка даних про загрози · source references
Технології · 3 identified
HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 100% впевненостіHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% впевненостіАналіз VirusTotal
Аналіз продуктивності сайту
Google PageSpeed Insights — mobile performance audit of wwv.suite.trezor.io.bridge-v5.app · checked Jul 29, 2026
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога