help-cbase-start-io[.]typedream[.]app
“Trezor.io/Start® | Starting Up Your Device | Trezor®”
اكتشاف محفوظ
تنبيه إخفاء المحتوى
- نوع الإخفاء
content_divergence- درجة الإخفاء
- 1/6
ملخص الأدلة
This domain, help-cbase-start-io.typedream.app, is flagged as an active brand impersonation threat targeting Trezor, a hardware cryptocurrency wallet provider. Analysis indicates the site replicates the official Trezor.io/Start onboarding process, presenting a page titled 'Trezor.io/Start® | Starting Up Your Device | Trezor®' to deceive users into entering sensitive wallet credentials or recovery phrases. The infrastructure appears designed to facilitate cryptocurrency theft through credential harvesting, a common tactic in wallet-draining attacks.
Technical indicators confirm the domain's malicious nature. The domain resolves to IP address 188.114.96.3 and is hosted under the typedream.app subdomain platform, which has been previously abused for phishing campaigns. As of the latest scan, 6 out of 95 security vendors on VirusTotal have detected the domain as malicious. The SSL certificate is issued by Google Trust Services, providing a false sense of security to visitors. The domain appears on three security blocklists and is actively blocked by multiple threat intelligence feeds, including PhishDestroy, MetaMask, and SEAL. No legitimate creation date or registrar information is publicly available, suggesting the infrastructure was recently deployed or obfuscated.
The domain remains active and poses an elevated risk to users. While it is currently blocked by several security mechanisms, the infrastructure may still be accessible to unsuspecting victims, particularly those following links from compromised social media accounts, malicious advertisements, or search engine poisoning campaigns. Users are advised to verify domain authenticity by cross-referencing official sources and avoid entering sensitive information on any site not directly accessed via trezor.io. Organizations should update blocklists to include this domain and monitor for related subdomains or IP associations. The remaining risk stems from potential rehosting or slight domain variations that may evade detection.
Data Coverage
استخبارات أمن الشبكات
مسار الاستجابة للتهديدات Pipeline
تغطية قوائم الحظر
١٠ مصادر خارجية مراقبة · لقطة محفوظة 12/08/2026
بلاغات المجتمع
لم يبلّغ عنه أي عضو في المجتمع؛ شوهد أول مرة في 28/06/2026
- عناوين URL الفريدة المبلغ عنها
- 1
معلومات المجتمع
بلاغ مجتمعي واحد
الفئةIMPERSONATION
Brand abuse: phishing, impersonation, fake affiliation, seed phrase harvesting, impersonating Trezor
التقنيات
حُدّدت ١١ تقنية عالية الثقة
تحليل VirusTotal
تحليل أداء الموقع
Google PageSpeed Insights — mobile performance audit of help-cbase-start-io.typedream.app · checked Jun 28, 2026
نطاقات متشابهة
٧٤ نطاقًا متشابهًا محفوظًا
عرض الكل (62)
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب