learn-en-bridge-sso[.]typedream[.]app
“Trezor Bridge® | Secure Connection for Trezor® Hardware Wallets”
learn-en-bridge-sso.typedream.app — 隐形 · 可达. 品牌冒充:Trezor; 诈骗类型:Brand Impersonation. 证据摘要: VirusTotal 18/94 (ADMINUSLabs, alphaMountain.ai, BitDefender, CRDF, CyRadar); URLQuery 3 alerts; URLScan malicious verdict; CF Radar malicious; cloaking observed; PhishDestroy score 100/100. 注册商: Typedream.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
PhishDestroy identifies learn-en-bridge-sso.typedream.app as an active credential theft domain posing as a legitimate SSO login page. This domain is designed to mimic official Single Sign-On portals, tricking users into entering their login credentials under false pretenses. The threat actor behind this campaign appears to be targeting users expecting secure access points, likely for account takeover or further exploitation in downstream attacks. This domain resolves to IP address 188.114.96.3 and is associated with a Google Trust Services SSL certificate, which may contribute to its appearance of legitimacy. VirusTotal analysis shows 12 out of 95 security vendors flagging this domain as malicious. The domain was registered through a privacy-protected registrar and currently shows no blocklist entries in major threat intelligence feeds. The precise creation date is not publicly disclosed, but the domain remains active at the time of this assessment. Users should immediately block access to this domain and avoid entering any credentials or sensitive information. Organizations are advised to update firewall rules and endpoint protections to block traffic to 188.114.96.3. The elevated risk level and confirmed malicious indicators warrant high-priority response actions to prevent credential compromise and potential follow-on attacks. Remaining risk is elevated due to the active nature of the domain and the use of trusted certificate authorities to enhance deception.
网络安全情报
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Cloudflare DNS | learn-en-bridge-sso.typedream.app |
malicious | Sinkholed |
| DNS4EU | learn-en-bridge-sso.typedream.app |
malicious | Sinkholed |
| OpenDNS | learn-en-bridge-sso.typedream.app |
phishing | Phishing Block |
威胁响应 Pipeline
公共封禁名单状态
所用技术 · 11 identified
JavaScript runtime built on Chrome V8 engine for server-side development.
JavaScript library for building user interfaces with component-based architecture.
Suite of cloud computing services running on Google infrastructure.
React framework for production with hybrid static and server rendering.
Content delivery network built on Google global edge infrastructure.
Performance monitoring tool that measures website speed from real users.
www.cloudflare.comWeb infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comModule bundler for modern JavaScript applications.
Third major version of HTTP protocol, built on QUIC for faster, more reliable connections.
VirusTotal 分析
存档证据
网站性能分析
Google PageSpeed Insights — mobile performance audit of learn-en-bridge-sso.typedream.app · checked Apr 15, 2026
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。