MALICIOUS — CRITICAL
Phishing- und Sicherheitsprüfung für io-start-trezer-start.pages.dev
io-start-trezer-start[.]
The domain io-start-trezer-start.pages.dev is identified as a high-risk brand_impersonation threat targeting Trezor, a hardware cryptocurrency wallet provider.
- VirusTotal
- 10/93
- Blocklists
- No stored match
- Verfügbarkeit
- Erreichbar · Zugang eingeschränkt · HTTP 403
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
io-start-trezer-start.pages.dev — Erreichbar · Zugang eingeschränkt (HTTP 403). Markenidentität: Trezor; Betrugstyp: Crypto Scam. Zusammenfassung der Beweislage: VirusTotal 10/93 (ADMINUSLabs, BitDefender, CyRadar, Fortinet, G-Data); URLScan malicious verdict; Google Safe Browsing flagged; PhishDestroy score 80/100. Registrar: Cloudflare.
Die ausführliche Analyse von PhishDestroy AI bleibt auf Englisch, damit der ursprüngliche forensische Bericht unverändert bleibt.
Evidence Analysis
The domain io-start-trezer-start.pages.dev is identified as a high-risk brand_impersonation threat targeting Trezor, a hardware cryptocurrency wallet provider. Analysis confirms the domain is currently offline, though it previously hosted a fraudulent wallet setup page titled 'Trezor Quick Start — Secure Your First Wallet.' This campaign specifically mimics Trezor’s onboarding process to deceive users into compromising their recovery seeds or private keys. Infrastructure analysis reveals the domain was flagged by 10 of 95 security vendors on VirusTotal, including detection by PhishDestroy, MetaMask, and SEAL. It was registered through Cloudflare, Inc. on September 02, 2020, and resolves to the IP address 172.66.47.42, hosted on Cloudflare’s network (AS13335). The SSL certificate is issued by Google Trust Services (WE1), a common feature in phishing domains leveraging Cloudflare’s proxy services. The domain appears on three security blocklists, and Google Safe Browsing has explicitly flagged it as phishing. The domain is currently offline, but historical activity and infrastructure patterns suggest it may resurface under a different subdomain or proxy configuration. Organizations and users are advised to block the domain and its associated IP at the network level. Cryptocurrency wallet providers should monitor for similar impersonation attempts, particularly those mimicking onboarding or recovery workflows. End users should verify domain authenticity by cross-referencing official documentation and avoiding interaction with unsolicited wallet setup pages.
Stored source results
Recorded verdicts and infrastructure observations for this domain.
Datenabdeckung12 recorded checks
Pipeline zur Reaktion auf Sicherheitsbedrohungen
Status der öffentlichen Sperrliste
Technologien · 3 identified
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
VirusTotal-Analyse
Archivierte Beweise
Website-Performanceanalyse
Google PageSpeed Insights — mobile performance audit of io-start-trezer-start.pages.dev · checked Apr 25, 2026
Nachweise und externe BerichteIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Wenn Sie Kontoanmeldeinformationen, persönliche oder Zahlungsinformationen eingegeben oder eine Datei von dieser Domain heruntergeladen haben, ergreifen Sie sofort Maßnahmen. Nachfolgend finden Sie Ressourcen, die Ihnen helfen, den Vorfall zu melden und sich zu schützen.
Melden Sie sich bei Ihren örtlichen Behörden
Wählen Sie Ihr Land aus, um Offizielle Kontakte im Bereich Cyberkriminalität oder einen Beschwerdeentwurf erstellen → zu erhalten.