bridg--trzor[.]pages[.]dev
“Trezor Bridge — Secure Your Hardware Wallet®”
证据摘要
PhishDestroy identifies bridg--trzor.pages.dev as an active generic phishing domain masquerading as a cryptocurrency wallet service. The domain employs a double-hyphen obfuscation technique ('bridg--trzor') to mimic the legitimate 'Bridge' protocol branding, targeting users seeking crypto wallet services. No specific drainer kit or cloned assets were observed in the current analysis, suggesting a preliminary phishing setup likely aimed at credential harvesting or cryptocurrency theft.
This domain resolves to IP 172.66.47.125 and is registered through Cloudflare, Inc., leveraging Google Trust Services for its SSL certificate. VirusTotal currently shows 2/95 detections, indicating evasion against signature-based detection systems. The domain is newly registered under Cloudflare’s Pages.dev platform, with no historical data available, and remains unlisted on Google Safe Browsing (GSB) and major blocklists as of this investigation. The risk level is marked as under_investigation due to limited telemetry and the absence of established threat actor fingerprints.
The domain remains active with no confirmed takedown or blocklist mitigation at this time. Users are advised to exercise extreme caution when encountering pages.dev subdomains promoting cryptocurrency services, especially those with obfuscated naming conventions. Immediate defensive actions include network-level blocking of the IP (172.66.47.125) and domain (bridg--trzor.pages.dev), alongside user awareness campaigns highlighting the risks of fake wallet phishing campaigns. Remaining risk is elevated due to the lack of detection signatures and the potential for rapid propagation across social engineering vectors. Regular re-evaluation of threat intelligence is recommended as this campaign matures.
Data Coverage
网络安全情报
威胁响应 Pipeline
阻止列表覆盖
监控中的外部数据源 10 个 · 已存快照 2026年8月13日
技术
识别出 3 项高置信度技术
VirusTotal 分析
网站性能分析
Google PageSpeed Insights — mobile performance audit of bridg--trzor.pages.dev · checked Apr 30, 2026
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。
检查任意域名
使用存储的阻止列表、WHOIS、DNS 和公共扫描证据进行威胁分析
立即扫描举报网络钓鱼
将可疑域名提交至我们的威胁数据库——保护社区
报告实时威胁动态
最近的网络钓鱼报告和观察到的可用性变化
监控