bredges--trwzer-web[.]pages[.]dev
“Trezor Bridge: Secure Connection for Your Hardware Wallet”
已存储的观测记录
观测到的标题差异
证据摘要
This domain, bredges--trwzer-web.pages.dev, is flagged for brand impersonation targeting Trezor, a hardware wallet provider. Analysis indicates the site mimics Trezor Bridge, a legitimate software component used to establish secure connections between Trezor devices and web browsers. The page title, 'Trezor Bridge: Secure Connection for Your Hardware Wallet,' directly replicates official branding, suggesting an intent to deceive users into interacting with malicious infrastructure under the guise of trusted software. No crypto drainer kit signatures were identified in initial scans, but the domain's structure and content align with tactics used in credential harvesting or malware distribution campaigns. Technical indicators reveal the following: the domain exhibits 0/95 detections on VirusTotal, indicating no prior flagging by security vendors at the time of analysis. It was registered on May 01, 2026, through Cloudflare, Inc., and resolves to the IP address 172.66.44.174. The SSL certificate is issued by Google Trust Services, a common feature in both legitimate and malicious domains leveraging Cloudflare's infrastructure. The domain appears on one security blocklist, as reported by PhishDestroy, and employs technologies such as HSTS, Cloudflare, and HTTP/3. Gridinsoft assigns a trust score of 0/100, further corroborating its suspicious nature. No detections were recorded in Google Safe Browsing databases at the time of this report. The domain is currently offline, having been taken down following initial detection. Response actions included reporting the domain to relevant blocklists and notifying the hosting provider to prevent further access. Despite its offline status, residual risk remains due to the potential for re-registration or migration to alternative infrastructure. Users who may have interacted with the domain are advised to revoke any active sessions, rotate credentials, and verify the integrity of their systems for unauthorized modifications. Organizations should monitor for similar impersonation attempts, particularly those leveraging subdomain services (e.g., *.pages.dev) to evade detection. Continuous scrutiny of domains mimicking hardware wallet software is recommended, given the high-value targets associated with cryptocurrency assets.
Data Coverage
网络安全情报
威胁响应 Pipeline
阻止列表覆盖
监控中的外部数据源 10 个 · 已存快照 2026年8月11日
检测时间线
-
VirusTotal
4 → 0
域名情报
技术详情DNS、TLS 名称和时间戳
技术
识别出 3 项高置信度技术
VirusTotal 分析
网站性能分析
Google PageSpeed Insights — mobile performance audit of bredges--trwzer-web.pages.dev · checked Jun 26, 2026
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。
检查任意域名
使用存储的阻止列表、WHOIS、DNS 和公共扫描证据进行威胁分析
立即扫描举报网络钓鱼
将可疑域名提交至我们的威胁数据库——保护社区
报告实时威胁动态
最近的网络钓鱼报告和观察到的可用性变化
监控