official-trzr-bridage[.]pages[.]dev
“Why Do You Need the Trezor Bridge for Your Hardware Wallet?”
official-trzr-bridage.pages.dev — 内容不可用. 品牌冒充:Trezor; 诈骗类型:Brand Impersonation. 证据摘要: VirusTotal 5/94 (ADMINUSLabs, Fortinet, Kaspersky, LevelBlue, Sophos); PhishDestroy score 70/100. 注册商: Cloudflare.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
PhishDestroy has flagged official-trzr-bridage.pages.dev as an active cryptocurrency wallet drainer site that specifically mimics the TRZR brand to trick users into authorizing malicious token transfers. The page is delivered through a Cloudflare Pages subdomain, indicating an attempt to exploit legitimate hosting infrastructure to bypass traditional blocklists. While the domain itself is newly registered and the payload has not yet been widely detected, the lure clearly targets TRZR wallet users with a spoofed “bridge” or “staking” interface designed to steal private keys or sign malicious transactions. Security researchers have observed drainer kits incorporating multi-chain bridging UIs that prompt victims for wallet connections under false pretenses—this site follows that pattern closely.
This domain was registered via Cloudflare, Inc. and resolves to IP 172.66.44.54. As of the latest scan, VirusTotal shows 5 out of 95 engines detecting the payload, and Google Safe Browsing (GSB) status remains unflagged, while the domain has not yet propagated to major threat intelligence blocklists. The domain uses a Google Trust Services SSL certificate to appear legitimate and was created recently, minimizing historical reputation data. These factors suggest a low-profile, targeted campaign likely aimed at early adopters or users seeking bridge services. The absence of detections and blocklist entries indicates the threat is still under the radar but highly active.
PhishDestroy assesses this site as a high-risk cryptocurrency drainer with active deployment. Users attempting to access official-trzr-bridage.pages.dev should immediately avoid any wallet connection prompts and report the domain to their security teams and wallet providers. Although the site remains unblocked by most browsers and AV engines, the drainer logic is operational and capable of stealing funds if wallet signatures are authorized. Until the payload is widely detected and blocked, users are advised to verify all bridge or staking URLs through official TRZR channels and use hardware wallets or transaction simulation tools before signing any requests. The risk level is currently under investigation but is expected to escalate as more victims report losses. Users are urged to treat this domain as hostile and share indicators to improve collective defense.
网络安全情报
威胁响应 Pipeline
公共封禁名单状态
取证情报
所用技术 · 3 identified
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
VirusTotal 分析
网站性能分析
Google PageSpeed Insights — mobile performance audit of official-trzr-bridage.pages.dev · checked Mar 25, 2026
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。