app-trzr-bridg-download[.]pages[.]dev
“How Can You Safely Complete the Trezor Bridge Download?”
app-trzr-bridg-download.pages.dev — 内容不可用. 品牌冒充:Trezor; 诈骗类型:Brand Impersonation. 证据摘要: VirusTotal 9/94 (ADMINUSLabs, BitDefender, ESET, Fortinet, G-Data); URLScan malicious verdict; PhishDestroy score 82/100. 注册商: Cloudflare.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
PhishDestroy identifies app-trzr-bridg-download.pages.dev as a live brand-impersonation page masquerading as the official Trezor Bridge installer. The domain intentionally copies Trezor’s download page title, “How Can You Safely Complete the Trezor Bridge Download?”, to trick users into downloading malicious software that harvests cryptocurrency wallet seed phrases. The page resolves to Google Cloud IP 188.114.96.3, carries a Google Trust Services SSL certificate, and remains unflagged on VirusTotal with zero detections out of 95 scanners. Registrar records show Cloudflare, Inc. as the listed provider, confirming the attacker’s use of cloud infrastructure to evade takedowns. This threat is classified as active brand impersonation under investigation, with a current risk level still being evaluated. The site exploits user trust in the Trezor brand and leverages Pages.dev’s free subdomain service to lower barriers to entry for phishing campaigns. Despite zero VirusTotal detections, the domain’s precise targeting and exact title mimicry indicate a sophisticated, purpose-built trap aimed at cryptocurrency users seeking legitimate wallet software. The lack of detections suggests either a very new campaign or evasion techniques undetected by conventional scanners. If you have already visited app-trzr-bridg-download.pages.dev, immediately disconnect your device from the internet, run a full antivirus scan, and verify the integrity of your Trezor device and seed phrase storage. Do not enter any recovery phrases, private keys, or wallet passwords on the site. Instead, download Trezor Bridge only from the official website trezor.io and confirm the correct domain spelling and HTTPS certificate. Report any unauthorized transactions to your wallet provider and consider transferring funds to a new, verified wallet if you suspect compromise.
网络安全情报
威胁响应 Pipeline
公共封禁名单状态
所用技术 · 3 identified
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
VirusTotal 分析
网站性能分析
Google PageSpeed Insights — mobile performance audit of app-trzr-bridg-download.pages.dev · checked Apr 13, 2026
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。