trezor-backup[.]io
“Suspected Phishing | Cloudflare”
Zusammenfassung der Beweislage
Analysis of trezor-backup.io indicates that the domain is currently active and classified as a crypto drainer, a threat that seeks to compromise cryptocurrency wallets or extract private keys. The domain appears on a single security blocklist and is explicitly blocked by the PhishDestroy service, suggesting that at least one reputable threat‑intelligence feed has flagged it for malicious activity. VirusTotal scanning reports that one out of ninety‑one security vendors returned a positive detection for the domain, providing additional corroboration of its suspicious nature.
No further reconnaissance data such as registrar details, IP address, hosting provider, SSL certificate information, HTTP response codes, Safe Browsing status, or Open Threat Exchange (OTX) entries were supplied, leaving the underlying infrastructure largely opaque. Consequently, the precise hosting environment, geographic location, and any associated malicious payloads cannot be confirmed at this time. Defenders should treat the domain as high‑risk given its elevated risk rating and active status.
Recommended mitigation steps include adding trezor-backup.io to network and endpoint deny‑lists, enforcing DNS filtering policies to block resolution, and monitoring outbound traffic for attempts to contact the domain. Continuous re‑evaluation is advised, as additional intelligence—such as detection signatures from more vendors, TLS certificate data, or observed command‑and‑control communications—may emerge and refine the threat profile. Organizations should also educate users about the danger of unsolicited requests for cryptocurrency seed phrases, reinforcing the principle that legitimate services never ask for private keys via unsolicited links.
Data Coverage
Pipeline zur Reaktion auf Sicherheitsbedrohungen
Blocklistenabdeckung
10 überwachte externe Feeds · gespeicherter Stand 11.08.2026
Erkennungszeitleiste
-
Domainstatus
Erreichbar → Nicht erreichbar
-
Domainstatus
Nicht erreichbar → Erreichbar
Community-Meldungen
Von 0 Community-Mitgliedern gemeldet; erstmals gesehen am 02.08.2026
- Eindeutige gemeldete URLs
- 1
Community-Erkenntnisse
1 Community-Meldung
KategorieIMPERSONATION
Brand abuse: phishing, impersonation, impersonating Trezor
Technologien
3 Technologien mit hoher Konfidenz erkannt
VirusTotal-Analyse
Website-Performanceanalyse
Google PageSpeed Insights — mobile performance audit of trezor-backup.io · checked Aug 2, 2026
Ähnliche Domains
74 gespeicherte ähnliche Domains
Alle anzeigen (62)
Wurden Sie von dieser Website betroffen?
Wenn Sie Kontoanmeldeinformationen, persönliche oder Zahlungsinformationen eingegeben oder eine Datei von dieser Domain heruntergeladen haben, ergreifen Sie sofort Maßnahmen. Nachfolgend finden Sie Ressourcen, die Ihnen helfen, den Vorfall zu melden und sich zu schützen.
Melden Sie sich bei Ihren örtlichen Behörden
Wählen Sie Ihr Land aus, um Offizielle Kontakte im Bereich Cyberkriminalität oder einen Beschwerdeentwurf erstellen → zu erhalten.
Jede beliebige Domain prüfen
Bedrohungsanalyse anhand gespeicherter Blocklisten, WHOIS, DNS und öffentlicher Scan-Beweise
Jetzt scannenPhishing melden
Melden Sie verdächtige Domains an unsere Bedrohungsdatenbank – schützen Sie die Community
MeldenEchtzeit-Bedrohungsfeed
Aktuelle Phishing-Meldungen und beobachtete Verfügbarkeitsänderungen
ÜberwachenBleiben Sie auf dem Laufenden, bleiben Sie sicher
Beobachten Sie aktuelle Bedrohungen oder legen Sie Widerspruch gegen diesen Eintrag ein, wenn Sie der Meinung sind, dass es sich um einen Fehlalarm handelt