trezior-hardware-live[.]vercel[.]app
“Trézor.io/Start® | Starting Up Your Device - Trézor®”
trezior-hardware-live.vercel.app — المحتوى غير متوفر. انتحال العلامة التجارية: Trezor; نوع الاحتيال: Crypto Scam. ملخص الأدلة: VirusTotal 15/95 (ADMINUSLabs, Criminal IP, alphaMountain.ai, BitDefender, CyRadar); URLScan malicious verdict; CF Radar malicious; PhishDestroy score 95/100. مسجّل النطاق: Vercel.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
Analysis of trezior-hardware-live.vercel.app as of July 25, 2026 shows that the site was used to impersonate the hardware‑wallet brand Trezor. The page title returned by the server, “Trézor.io/Start® | Starting Up Your Device - Trézor®”, directly references the legitimate Trezor brand, confirming a brand‑impersonation tactic. The domain is hosted on Vercel infrastructure and serves content over HTTPS with a Google Trust Services / WR1 certificate, indicating a valid TLS chain but offering no assurance of legitimacy. HTTP response code 451 signals that the content was unavailable due to legal reasons, consistent with the reported “taken offline” status. DNS resolution points to IP 64.29.17.67, which belongs to Amazon.com, Inc. (AS16509) in the United States, a common hosting provider for disposable phishing sites.
The site employed HSTS, a standard security header, but this does not mitigate the underlying impersonation. VirusTotal scans flagged the domain by 15 of 95 security vendors, and the domain appears on at least one external blocklist, confirming that multiple security engines consider it malicious. PhishDestroy has also listed the site as blocked. The registrar information shows the domain was registered through Vercel Inc., a platform that allows rapid deployment of short‑lived domains.
No nameserver data were returned, and the domain is currently offline, limiting immediate observation of payloads. Defenders should continue to block the domain at network and email gateways, ensure that any URL filtering solutions reference the observed blocklist entries, and monitor for additional domains that use the same Vercel‑based deployment pattern targeting Trezor users. Threat intelligence feeds should be updated with the observed indicators—domain name, IP address, SSL certificate fingerprint, and HTTP 451 response—to support rapid detection of re‑hosted copies.
استخبارات أمن الشبكات
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
التقنيات · 2 identified
HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org ثقة 100٪تحليل VirusTotal
الأدلة المؤرشفة
الأدلة والتقارير الخارجية
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب