trrezorawallet[.]webflow[.]io
“Trezor wallet Model One | The Original Crypto Hardware Wallet”
trrezorawallet.webflow.io — Inhalt nicht verfügbar. Markenidentität: Trezor; Betrugstyp: Brand Impersonation. Zusammenfassung der Beweislage: VirusTotal 8/91 (ChainPatrol, CyRadar, Emsisoft, Fortinet, Kaspersky); URLScan malicious verdict; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 74/100. Registrar: MarkMonitor.
Die ausführliche Analyse von PhishDestroy AI bleibt auf Englisch, damit der ursprüngliche forensische Bericht unverändert bleibt.
This domain operates as a brand impersonation threat specifically targeting Trezor hardware wallet users. Analysis indicates the site replicates the official Trezor Model One interface, presenting itself as "The Original Crypto Hardware Wallet" to deceive visitors into entering sensitive recovery phrases or private keys. The objective appears to be asset theft through crypto drainer mechanisms, where unauthorized transactions are initiated once credentials are compromised. The domain's infrastructure and content are designed to exploit trust in the Trezor brand, potentially leading to irreversible financial losses for victims. Infrastructure analysis reveals multiple high-risk indicators. The domain, trrezorawallet.webflow.io, was created on June 15, 2026, through MarkMonitor, Inc., and resolves to the IP address 104.18.36.248. It is currently flagged by 13 out of 95 security vendors on VirusTotal and appears on three independent security blocklists. Additionally, the domain has been proactively blocked by multiple security platforms, including MetaMask, PhishDestroy, and SEAL. The SSL certificate is issued by Google Trust Services, which, while legitimate, does not mitigate the malicious intent of the site. The combination of these factors confirms the domain's role in facilitating fraudulent activities. Users who visited trrezorawallet.webflow.io should take immediate action to secure their assets. If any credentials, recovery phrases, or private keys were entered on the site, affected wallets must be considered compromised. Transfer all remaining assets to a new, secure wallet using a clean device and a verified recovery process. Monitor all linked accounts for unauthorized transactions and enable multi-factor authentication where available. Report the incident to relevant security teams and consider filing a report with local cybercrime authorities. Given the high-risk nature of this domain, affected users should also conduct a full security audit of their devices to rule out additional compromise.
Pipeline zur Reaktion auf Sicherheitsbedrohungen
Status der öffentlichen Sperrliste
Gespeicherte Aufnahme
Domain-Intelligenz
Technische DetailsDNS, SSL-SANs, Zeitstempel
Technologien · 2 identified
Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100 % KonfidenzHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100 % KonfidenzVirusTotal-Analyse
Website-Performanceanalyse
Google PageSpeed Insights — mobile performance audit of trrezorawallet.webflow.io · checked Jun 25, 2026
Nachweise und externe Berichte
Wurden Sie von dieser Website betroffen?
Wenn Sie Kontoanmeldeinformationen, persönliche oder Zahlungsinformationen eingegeben oder eine Datei von dieser Domain heruntergeladen haben, ergreifen Sie sofort Maßnahmen. Nachfolgend finden Sie Ressourcen, die Ihnen helfen, den Vorfall zu melden und sich zu schützen.
Melden Sie sich bei Ihren örtlichen Behörden
Wählen Sie Ihr Land aus, um Offizielle Kontakte im Bereich Cyberkriminalität oder einen Beschwerdeentwurf erstellen → zu erhalten.
Jede beliebige Domain prüfen
Bedrohungsanalyse anhand gespeicherter Blocklisten, WHOIS, DNS und öffentlicher Scan-Beweise
Jetzt scannenPhishing melden
Melden Sie verdächtige Domains an unsere Bedrohungsdatenbank – schützen Sie die Community
MeldenEchtzeit-Bedrohungsfeed
Aktuelle Phishing-Meldungen und beobachtete Verfügbarkeitsänderungen
ÜberwachenBleiben Sie auf dem Laufenden, bleiben Sie sicher
Beobachten Sie aktuelle Bedrohungen oder legen Sie Widerspruch gegen diesen Eintrag ein, wenn Sie der Meinung sind, dass es sich um einen Fehlalarm handelt