trezor[.]io-start-suite[.]io
“Trezor Suite Web”
trezor.io-start-suite.io — خطأ في الخادم (HTTP 502). انتحال العلامة التجارية: Trezor; نوع الاحتيال: Brand Impersonation. ملخص الأدلة: VirusTotal 3/91 (Fortinet, Gridinsoft, Kaspersky); URLScan malicious verdict; Spamhaus DBL_SPAM; PhishDestroy score 66/100. مسجّل النطاق: NiceNIC.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
Analysis of the domain trezor.io-start-suite.io indicates it is a brand impersonation threat targeting Trezor, a cryptocurrency hardware wallet provider. The domain was registered on June 23, 2026, through NICENIC INTERNATIONAL GROUP CO., LIMITED, a registrar frequently associated with high-risk domains. Infrastructure analysis reveals the domain resolves to the IP address 2.27.1.18, hosted under AS210546 (CHSL ONE LTD) in Germany. Nameservers are configured to a.dnspod.com, b.dnspod.com, and c.dnspod.com, a pattern observed in other phishing campaigns leveraging DNSPod’s DNS services. The domain’s SSL certificate was issued by Let’s Encrypt (YR2), a common choice for both legitimate and malicious sites due to its free and automated issuance process.
Detection data shows the domain appears on one security blocklist, specifically PhishDestroy, and is flagged by 3 of 91 security vendors on VirusTotal, confirming its classification as malicious. Gridinsoft assigns a trust score of 0/100, further supporting its high-risk status. As of July 23, 2026, the domain is offline, though this does not preclude future reactivation or migration to a new infrastructure. The scam type is explicitly categorized as brand impersonation, with Trezor identified as the targeted brand.
No additional details about the exact content or functionality of the site are available, as the domain has not been actively crawled or analyzed for specific phishing mechanisms. Defenders should treat this domain as a confirmed threat and block it at the DNS, proxy, and endpoint levels. Monitoring for related domains registered through the same registrar or resolving to the same IP range is recommended to identify potential follow-up campaigns. Given the domain’s recent creation and rapid detection by security vendors, organizations should prioritize awareness for users handling cryptocurrency assets.
استخبارات أمن الشبكات Registrar context
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
Latest Classified Outcome 2026-08-16 12:53:50 UTC
تحليل VirusTotal
الأدلة والتقارير الخارجية
PD-20260624-6BD4C3 Recipient: abuse@chosting.solutions هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب