tterezrwallet[.]webflow[.]io
“Trezor* Wallet@ - The official wallet”
Zusammenfassung der Beweislage
The domain tterezrwallet.webflow.io was created on May 08, 2013 and is registered through MarkMonitor, Inc. It resolves to the IP address 104.18.36.248, which is hosted within Cloudflare’s AS13335 network in the United States and served via the nameservers journey.ns.cloudflare.com and lamar.ns.cloudflare.com. The site presented a page title of "Trezor* Wallet@ - The official wallet," explicitly targeting the Trezor brand and was classified as a crypto scam. The SSL certificate was issued by Google Trust Services under the WE1 authority, indicating a valid HTTPS endpoint, while the HTTP response returned a 404 status code, suggesting the content is no longer accessible.
Technical fingerprints reveal the use of Cloudflare services and HTTP/3 protocol. Threat intelligence indicates that 14 of 95 security vendors on VirusTotal flagged the domain, and it appears on a single security blocklist. The domain has been blocked by PhishDestroy and is currently listed as offline.
While the historical data confirms the presence of brand impersonation and malicious infrastructure, real‑time activity cannot be observed due to the offline status. Defenders should retain the indicator set—including the domain name, resolved IP, registrar, SSL issuer, and detection counts—in their threat‑intel feeds and ensure that any residual references in logs or firewall rules are treated as malicious. Continuous monitoring of Cloudflare‑hosted IP ranges for similar impersonation attempts is recommended, as the infrastructure may be reused for future campaigns targeting cryptocurrency users.
Data Coverage
Erkenntnisse zur Netzwerksicherheit
Pipeline zur Reaktion auf Sicherheitsbedrohungen
Blocklistenabdeckung
10 überwachte externe Feeds · gespeicherter Stand 13.08.2026
Erkennungszeitleiste
-
Cloudflare Radar
Cloudflare-Radar-Scan gespeichert · Scan öffnen
-
Domainstatus
Erreichbar → Nicht erreichbar
-
Cloudflare Radar
Cloudflare-Radar-Scan gespeichert · Scan öffnen
Community-Meldungen
Von 1 Community-Mitglied gemeldet; erstmals gesehen am 07.11.2025
- Gespeicherte Meldungen
- 1
- Eindeutige gemeldete URLs
- 1
Community-Erkenntnisse
1 Community-Meldung
KategoriePHISHING
The PhishFort Detection System has flagged this as a domain threat, classified as phishing. Associated tags: , . Threat detected at 2025-11-07T01:30:30.297Z.
Technologien
2 Technologien mit hoher Konfidenz erkannt
VirusTotal-Analyse
Ähnliche Domains
74 gespeicherte ähnliche Domains
Alle anzeigen (62)
Wurden Sie von dieser Website betroffen?
Wenn Sie Kontoanmeldeinformationen, persönliche oder Zahlungsinformationen eingegeben oder eine Datei von dieser Domain heruntergeladen haben, ergreifen Sie sofort Maßnahmen. Nachfolgend finden Sie Ressourcen, die Ihnen helfen, den Vorfall zu melden und sich zu schützen.
Melden Sie sich bei Ihren örtlichen Behörden
Wählen Sie Ihr Land aus, um Offizielle Kontakte im Bereich Cyberkriminalität oder einen Beschwerdeentwurf erstellen → zu erhalten.
Jede beliebige Domain prüfen
Bedrohungsanalyse anhand gespeicherter Blocklisten, WHOIS, DNS und öffentlicher Scan-Beweise
Jetzt scannenPhishing melden
Melden Sie verdächtige Domains an unsere Bedrohungsdatenbank – schützen Sie die Community
MeldenEchtzeit-Bedrohungsfeed
Aktuelle Phishing-Meldungen und beobachtete Verfügbarkeitsänderungen
ÜberwachenBleiben Sie auf dem Laufenden, bleiben Sie sicher
Beobachten Sie aktuelle Bedrohungen oder legen Sie Widerspruch gegen diesen Eintrag ein, wenn Sie der Meinung sind, dass es sich um einen Fehlalarm handelt