suites--trezr[.]pages[.]dev
“Trezor Suite Guide | Official Interface for Trezor® Hardware Wallets”
Tóm tắt bằng chứng
PhishDestroy identifies an active phishing campaign targeting cryptocurrency users through the domain suites--trezr.pages.dev, which mimics legitimate wallet services to harvest credentials and seed phrases. This domain is specifically designed to deceive visitors into entering sensitive wallet information under the guise of a Trezor wallet login or recovery portal. The threat actor leverages Cloudflare Pages to host the phishing content, which resolves to IP 172.66.47.172 and utilizes a Google Trust Services SSL certificate to appear legitimate. The domain’s rapid deployment and low detection rate on VirusTotal (9/95 engines as of the latest scan) indicate an evasive operation likely designed to bypass traditional security measures. This domain was flagged by PhishDestroy with the unique seed identifier a9155d. The domain is registered through Cloudflare, Inc., a common choice for threat actors seeking to obfuscate hosting origins. As of the latest intelligence, VirusTotal detections remain at 9/95, suggesting minimal signature-based detection despite the domain’s malicious intent. The absence of blocklist entries further implies the threat is in its early stages, increasing the risk of exposure to unsuspecting users. The use of a Google Trust Services SSL certificate adds a layer of perceived legitimacy, potentially tricking users into overlooking red flags such as the unusual double-hyphen in the domain name or the Cloudflare Pages subdomain structure. Users who have visited suites--trezr.pages.dev should immediately cease any interaction with the site and avoid entering any cryptocurrency wallet credentials, seed phrases, or personal information. If credentials were entered, users must transfer funds to a new wallet immediately and revoke any associated API keys or permissions. Clear browser cache and cookies related to the domain, and consider running a malware scan on the device used for access. Report the domain to your antivirus provider and local cybercrime units to aid in blocking efforts. Enable multi-factor authentication (MFA) on all cryptocurrency accounts and use hardware wallets where possible to mitigate future risks. Monitor financial accounts closely for unauthorized transactions. This domain remains active and should be treated as a high-risk phishing vector until further notice.
Data Coverage
Tình báo an ninh mạng
Pipeline ứng phó với các mối đe dọa
Phạm vi danh sách chặn
10 nguồn ngoài được giám sát · ảnh chụp lưu ngày 13/08/2026
10 nguồn ngoài được giám sát Không trùng khớp
Phân tích của VirusTotal
Phân tích hiệu suất trang
Google PageSpeed Insights — mobile performance audit of suites--trezr.pages.dev · checked Apr 19, 2026
Bạn có bị ảnh hưởng bởi trang web này không?
Nếu bạn đã nhập thông tin xác thực tài khoản, thông tin cá nhân hoặc thông tin thanh toán hoặc đã tải xuống tệp từ miền này, hãy hành động ngay lập tức. Dưới đây là các nguồn lực giúp bạn báo cáo vụ việc và bảo vệ chính mình.
Hãy báo cáo với chính quyền địa phương
Chọn quốc gia của bạn để nhận liên hệ tội phạm mạng chính thức hoặc soạn thảo đơn khiếu nại →.
Kiểm tra bất kỳ tên miền nào
Phân tích mối đe dọa bằng cách sử dụng danh sách chặn được lưu trữ, WHOIS, DNS và bằng chứng quét công khai
Quét ngayBáo cáo lừa đảo qua email
Hãy gửi các tên miền đáng ngờ đến cơ sở dữ liệu mối đe dọa của chúng tôi — để bảo vệ cộng đồng
Báo cáoDòng tin tức về các mối đe dọa thời gian thực
Các báo cáo lừa đảo gần đây và những thay đổi về tính khả dụng được quan sát thấy
Theo dõiLuôn cập nhật thông tin, luôn an toàn
Theo dõi các mối đe dọa đang diễn ra hoặc phản đối danh sách này nếu bạn cho rằng đây là kết quả báo động sai