black-moon-trw[.]coteenancee[.]workers[.]dev
“Trezor Suite”
ملاحظة محفوظة
تباين العناوين المرصود
ملخص الأدلة
This analysis concerns domain black-moon-trw.coteenancee.workers.dev identified as a brand_impersonation incident targeting Trezor cryptocurrency wallet services. The domain is currently reported as offline, indicating successful disruption or takedown following detection by security systems.
Infrastructure telemetry shows TLS certificates issued via Let's Encrypt, with hosting routed through Cloudflare, Inc. The service leverages HTTP/3, HSTS enforcement, and reverse proxy infrastructure consistent with content delivery obfuscation. The domain resolves to IP address 172.67.185.62. Security telemetry indicates 15 of 95 VirusTotal vendors flagged the domain as malicious, and it appears on 1 independent security blocklist. No explicit creation date is available in current intelligence, limiting temporal attribution.
Content and behavioral indicators, including the page title 'Trezor Suite', strongly indicate brand impersonation designed to mimic legitimate cryptocurrency wallet software interfaces. Such patterns are consistent with phishing campaigns aimed at credential harvesting and seed phrase theft. Despite current offline status, historical exposure suggests prior user interaction risk and potential cached propagation across CDN nodes. Risk assessment classifies the infrastructure as elevated due to confirmed vendor detections and brand abuse signals. Recommended mitigations include enforcing domain and IP blocking across DNS, web gateways, and endpoint protection systems, correlating SIEM logs for any connections to 172.67.185.62, and conducting user awareness checks for exposure to fake wallet interfaces. Additionally, defenders should monitor for derivative Cloudflare Workers subdomains and apply heuristic detection for similar impersonation templates.
Data Coverage
مسار الاستجابة للتهديدات Pipeline
تغطية قوائم الحظر
١٠ مصادر خارجية مراقبة · لقطة محفوظة 12/08/2026
المخطط الزمني للاكتشاف
-
VirusTotal
None ← 1
-
VirusTotal
12 ← 15
بلاغات المجتمع
أبلغ عنه عضو واحد في المجتمع؛ شوهد أول مرة في 01/06/2026
- البلاغات المحفوظة
- 1
- عناوين URL الفريدة المبلغ عنها
- 1
معلومات المجتمع
بلاغ مجتمعي واحد
الفئةIMPERSONATION
Brand abuse: phishing, seed phrase harvesting, impersonation, impersonating Trezor
التقنيات
حُدّدت ٣ تقنيات عالية الثقة
تحليل VirusTotal
تحليل أداء الموقع
Google PageSpeed Insights — mobile performance audit of black-moon-trw.coteenancee.workers.dev · checked Jun 26, 2026
نطاقات متشابهة
٧٤ نطاقًا متشابهًا محفوظًا
عرض الكل (62)
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب