io-trezorsuite[.]ltd
io-trezorsuite.ltd — المحتوى غير متوفر. انتحال العلامة التجارية: Trezor; نوع الاحتيال: Brand Impersonation. ملخص الأدلة: VirusTotal 13/91 (alphaMountain.ai, BitDefender, CRDF, CyRadar, Forcepoint ThreatSeeker); URLQuery 4 alerts; Spamhaus DBL_PHISH; PhishDestroy score 98/100. مسجّل النطاق: GNAME.COM.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
io-trezorsuite.ltd is a confirmed brand impersonation scam designed to mimic Trezor, a leading hardware wallet provider. The domain is currently offline, but its short-lived existence posed a credible threat to cryptocurrency users seeking official support or wallet access. This specific threat type, brand impersonation, relies on deceiving users into entering sensitive credentials or connecting their wallets to malicious interfaces.
PhishDestroy’s analysis reveals that io-trezorsuite.ltd was created on March 25, 2026, and registered through GNAME.COM PTE. LTD., a registrar commonly associated with high-risk domains. The domain resolves to IP address 188.114.97.3, and it appears on 1 security blocklist. VirusTotal data shows that 4 out of 95 security vendors flagged this domain as malicious, indicating a moderate detection rate. The domain was registered solely to impersonate the Trezor brand, leveraging the recognizable name to trick users into believing they were on an official Trezor website.
Given that io-trezorsuite.ltd has been taken offline, the immediate risk to users is minimized. However, PhishDestroy recommends that users remain vigilant against similar domains that may arise, as brand impersonation attacks against cryptocurrency platforms are persistent. Users should always verify the official URL by navigating directly from Trezor’s official website or app, and avoid clicking on links from unsolicited emails or messages. If any credentials or wallet details were entered on this domain, users should immediately change their passwords and enable two-factor authentication, and contact Trezor support for further assistance.
استخبارات أمن الشبكات
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | io-trezorsuite.ltd |
malicious | Sinkholed |
| Hagezi Threat Feed | io-trezorsuite.ltd |
malicious | Sinkholed |
| Hagezi Threat Feed | api18.io-trezorsuite.ltd |
malicious | Sinkholed |
| DNS4EU | api18.io-trezorsuite.ltd |
malicious | Sinkholed |
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
لقطة محفوظة
معلومات النطاق
التفاصيل الفنيةDNS، أسماء المجال البديلة (SAN) في بروتوكول SSL، الطوابع الزمنية
ICANN OVERSIGHT
الاعتماد وسياق RAA
الاعتماد وسياق RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
التقنيات · 11 identified
Amazon Web Services (AWS) is a comprehensive cloud services platform offering compute power, database storage, content delivery and other functionality.
aws.amazon.com ثقة 100٪Zendesk is a cloud-based help desk management solution offering customizable tools to build customer service portal, knowledge base and online communities.
zendesk.com ثقة 100٪Usercentrics is a SaaS enterprise solution for Consent Management (CMP) that helps enterprise customers to obtain, manage and document the user consent.
usercentrics.com ثقة 100٪Sendinblue is an email marketing solution for small and medium-sized businesses that want to send and automate email marketing campaigns.
www.sendinblue.com ثقة 100٪Hotjar is a suite of analytic tools to assist in the gathering of qualitative data, providing feedback through tools such as heatmaps, session recordings, and surveys.
www.hotjar.com ثقة 100٪HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org ثقة 100٪Facebook pixel is an analytics tool that allows you to measure the effectiveness of your advertising.
facebook.com ثقة 100٪Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com ثقة 100٪Amazon Simple Email Service (SES) is an email service that enables developers to send mail from within any application.
aws.amazon.com ثقة 100٪Amazon S3 or Amazon Simple Storage Service is a service offered by Amazon Web Services (AWS) that provides object storage through a web service interface.
aws.amazon.com ثقة 100٪تحليل VirusTotal
الأدلة والتقارير الخارجية
PD-20260618-10C6AE Recipient: complaint@gname.com هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب