recovery-trezor[.]net
“Trezor Suite”
recovery-trezor.net — Inhalt nicht verfügbar (HTTP 502). Markenidentität: Trezor; Betrugstyp: Wallet/seed Phishing. Zusammenfassung der Beweislage: VirusTotal 21/95 (ADMINUSLabs, Criminal IP, alphaMountain.ai, BitDefender, CRDF); URLQuery 100 det.; URLScan malicious verdict; Spamhaus DBL_PHISH; PhishDestroy score 95/100. Registrar: Gname.
Die ausführliche Analyse von PhishDestroy AI bleibt auf Englisch, damit der ursprüngliche forensische Bericht unverändert bleibt.
The risk level for the domain recovery-trezor.net is elevated, with the specific threat type being brand impersonation. This domain impersonates Trezor, a well-known cryptocurrency hardware wallet brand, and poses a significant risk to users who may mistake it for the legitimate site.
Infrastructure analysis reveals that recovery-trezor.net is registered through Gname.com Pte. Ltd. and resolves to the IP address 178.16.54.185, located in the Netherlands under the Autonomous System AS202412 Omegatech LTD. The domain was created on December 14, 2025, and currently lacks an SSL certificate, which is a red flag for security-conscious users. Additionally, 21 out of 95 security vendors on VirusTotal flag this domain, and it appears on one security blocklist, notably PhishDestroy. The page title 'Trezor Suite' further adds to the deceptive nature of the site, as it mimics the official title of Trezor's software.
To mitigate the risks associated with brand impersonation, users are advised to verify the domain name and SSL certificate status of any site they visit, especially when handling sensitive information such as cryptocurrency wallets. Organizations should update their security blocklists to include this domain and educate their users on the importance of recognizing and avoiding impersonation attacks. Regular monitoring of domain registrations and IP addresses associated with known brands can also help in early detection and prevention of such threats.
Pipeline zur Reaktion auf Sicherheitsbedrohungen
Status der öffentlichen Sperrliste
Gespeicherte Aufnahme
Domain-Intelligenz
Technische DetailsDNS, SSL-SANs, Zeitstempel
ICANN OVERSIGHT
Akkreditierung und RAA-Kontext
Akkreditierung und RAA-Kontext
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
VirusTotal-Analyse
Nachweise und externe Berichte
Wurden Sie von dieser Website betroffen?
Wenn Sie Kontoanmeldeinformationen, persönliche oder Zahlungsinformationen eingegeben oder eine Datei von dieser Domain heruntergeladen haben, ergreifen Sie sofort Maßnahmen. Nachfolgend finden Sie Ressourcen, die Ihnen helfen, den Vorfall zu melden und sich zu schützen.
Melden Sie sich bei Ihren örtlichen Behörden
Wählen Sie Ihr Land aus, um Offizielle Kontakte im Bereich Cyberkriminalität oder einen Beschwerdeentwurf erstellen → zu erhalten.
Jede beliebige Domain prüfen
Bedrohungsanalyse anhand gespeicherter Blocklisten, WHOIS, DNS und öffentlicher Scan-Beweise
Jetzt scannenPhishing melden
Melden Sie verdächtige Domains an unsere Bedrohungsdatenbank – schützen Sie die Community
MeldenEchtzeit-Bedrohungsfeed
Aktuelle Phishing-Meldungen und beobachtete Verfügbarkeitsänderungen
ÜberwachenBleiben Sie auf dem Laufenden, bleiben Sie sicher
Beobachten Sie aktuelle Bedrohungen oder legen Sie Widerspruch gegen diesen Eintrag ein, wenn Sie der Meinung sind, dass es sich um einen Fehlalarm handelt