trezor[.]la
Phishing- und Sicherheitsprüfung für trezor.la
“Trezor钱包-Trezor钱包介绍-Trezor钱包官网入口-Trezor官方安卓下载”
trezor.la — Letzter bekanntermaßen aktiv (HTTP 200). Markenidentität: Trezor; Betrugstyp: Crypto Scam. Zusammenfassung der Beweislage: VirusTotal 16/95 (alphaMountain.ai, BitDefender, CRDF, CyRadar, ESET); Spamhaus DBL_PHISH; PhishDestroy score 100/100. Registrar: Name.com.
Die ausführliche Analyse von PhishDestroy AI bleibt auf Englisch, damit der ursprüngliche forensische Bericht unverändert bleibt.
Analysis indicates that the domain trezor.la was a confirmed crypto scam impersonating Trezor, a well-known hardware wallet provider. The domain was registered on September 8, 2024, through Name.com LLC and has since been taken offline. Infrastructure analysis reveals it was hosted behind Cloudflare (AS13335) at IP 188.114.97.3, with nameservers aaden.ns.cloudflare.com and sierra.ns.cloudflare.com. The SSL certificate was issued by DigiCert Inc under the Encryption Everywhere DV TLS CA - G2 chain, a common choice for both legitimate and malicious sites. The page title, 'Trezor钱包-Trezor钱包介绍-Trezor钱包官网入口-Trezor官方安卓下载,' explicitly targets Chinese-speaking users, suggesting a localized phishing campaign aimed at Trezor wallet users seeking official software downloads.
Detection data supports the malicious classification: the domain appears on at least one security blocklist and is flagged by 16 of 95 security vendors in VirusTotal scans. AlienVault OTX records it in 14 threat intelligence pulses, indicating active tracking by the security community. Gridinsoft assigns it a trust score of 0/100, and PhishDestroy has blocked it. The HTTP status returned a 200 code prior to takedown, confirming the site was operational. Technologies detected include Google Cloud, Nginx, and Google Cloud CDN, which are frequently used in both legitimate and fraudulent infrastructure.
While the exact content of the site remains unanalyzed, the combination of domain registration details, hosting provider, detection data, and page title strongly supports the classification as a brand impersonation scam targeting cryptocurrency users. Defenders should treat this domain as malicious and include it in blocklists and monitoring systems. The takedown status reduces immediate risk, but similar domains may emerge using the same infrastructure or targeting patterns.
Pipeline zur Reaktion auf Sicherheitsbedrohungen
Status der öffentlichen Sperrliste
Technologien · 3 identified
Nginx is a web server that can also be used as a reverse proxy, load balancer, mail proxy and HTTP cache.
nginx.org 100 % KonfidenzCloud CDN uses Google's global edge network to serve content closer to users.
cloud.google.com 100 % KonfidenzVirusTotal-Analyse
Archivierte Beweise
Nachweise und externe Berichte
Wurden Sie von dieser Website betroffen?
Wenn Sie Kontoanmeldeinformationen, persönliche oder Zahlungsinformationen eingegeben oder eine Datei von dieser Domain heruntergeladen haben, ergreifen Sie sofort Maßnahmen. Nachfolgend finden Sie Ressourcen, die Ihnen helfen, den Vorfall zu melden und sich zu schützen.
Melden Sie sich bei Ihren örtlichen Behörden
Wählen Sie Ihr Land aus, um Offizielle Kontakte im Bereich Cyberkriminalität oder einen Beschwerdeentwurf erstellen → zu erhalten.
Jede beliebige Domain prüfen
Bedrohungsanalyse anhand gespeicherter Blocklisten, WHOIS, DNS und öffentlicher Scan-Beweise
Jetzt scannenPhishing melden
Melden Sie verdächtige Domains an unsere Bedrohungsdatenbank – schützen Sie die Community
MeldenEchtzeit-Bedrohungsfeed
Aktuelle Phishing-Meldungen und beobachtete Verfügbarkeitsänderungen
ÜberwachenBleiben Sie auf dem Laufenden, bleiben Sie sicher
Beobachten Sie aktuelle Bedrohungen oder legen Sie Widerspruch gegen diesen Eintrag ein, wenn Sie der Meinung sind, dass es sich um einen Fehlalarm handelt