en-us-trzeo-iosrt[.]pages[.]dev
“Trezor Wallet Start Guide - Secure Your Crypto Today”
en-us-trzeo-iosrt.pages.dev — 内容不可用. 品牌冒充:Google; 诈骗类型:Brand Impersonation. 证据摘要: VirusTotal 3/94 (Fortinet, Kaspersky, LevelBlue); URLScan malicious verdict; PhishDestroy score 65/100. 注册商: Cloudflare.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
PhishDestroy identifies en-us-trzeo-iosrt.pages.dev as an active Google Trust-themed phishing site specifically targeting Apple iOS users. The domain resolves to IP 188.114.97.3 through Cloudflare and relies on a Google Trust Services SSL certificate to masquerade as legitimate, exploiting user trust in well-known brands. Analysis shows zero detections on VirusTotal (3/95 engines), highlighting how static scanners often miss sophisticated browser-based scams that rely on lookalike interfaces and real-time content delivery. This domain was flagged while impersonating Apple's software update portals, a tactic commonly used to harvest Apple ID credentials or deploy malware under the guise of security alerts.
Registered infrastructure indicates this domain was provisioned through Cloudflare, Inc., leveraging their edge network to evade hosting-level takedowns and persist with minimal downtime. While the SSL certificate issuance through Google Trust Services adds to its authenticity, the certificate itself is valid only for the phishing domain, not Apple’s official services. Current threat intelligence shows this site remains active with no active blocklist entries as of the latest scan, allowing it to operate unchallenged in phishing feeds. The use of Cloudflare’s proxy also conceals the true origin and operator, complicating attribution and takedown efforts.
Users who visited en-us-trzeo-iosrt.pages.dev should immediately check for unauthorized Apple ID logins, revoke suspicious sessions, and scan devices for malware using trusted antivirus tools. If you entered credentials, change your Apple ID password immediately and enable two-factor authentication. Avoid clicking on unexpected update prompts or links claiming to be from Apple—always navigate directly to apple.com via a verified browser session. Report any interactions with this domain to your security team or via PhishDestroy’s submission portal using seed fcea39 for tracked analysis.
网络安全情报
威胁响应 Pipeline
公共封禁名单状态
VirusTotal 分析
网站性能分析
Google PageSpeed Insights — mobile performance audit of en-us-trzeo-iosrt.pages.dev · checked Apr 9, 2026
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。