trezor-data[.]gxtigroup[.]com
“Index of /”
Zusammenfassung der Beweislage
The domain trezor-data.gxtigroup.com was observed being used in a brand‑impersonation campaign targeting the cryptocurrency hardware wallet provider Trezor. VirusTotal records show that 11 of 93 scanned security vendors flagged the domain as malicious, indicating a moderate level of detection across the ecosystem. The site was registered on 21 February 2026 and, at the time of analysis (23 July 2026), the host has taken the service offline. PhishDestroy listed the domain on its blocklist, and the domain also appears on a single external security blocklist, reinforcing the view that it was actively being used for malicious purposes.
The SSL certificate presented is identified as “R12”, a detail that aligns with typical short‑lived certificates used by transient phishing infrastructure. Gridinsoft assigned a trust score of 0 out of 100, the lowest possible rating, further confirming the domain’s lack of legitimacy. The HTTP response returned the generic page title “Index of /”, which provides no functional content but is consistent with a placeholder page often employed to hide malicious payloads. The campaign has been classified as a crypto‑scam, and the domain explicitly impersonates the Trezor brand, suggesting that victims may have been directed to submit wallet credentials or seed phrases.
Because the hosting IP, registrar, and ASN information were not disclosed in the available intelligence, the full infrastructure footprint remains partially unknown. Defenders should ensure that the domain is added to DNS and URL filtering blocklists, monitor for any residual traffic to the associated IP ranges, and update incident response playbooks to include Trezor‑related impersonation indicators. Continuous re‑evaluation is advised in case the domain is re‑hosted or the underlying infrastructure is reused in future campaigns.
Data Coverage
Pipeline zur Reaktion auf Sicherheitsbedrohungen
Blocklistenabdeckung
10 überwachte externe Feeds · gespeicherter Stand 12.08.2026
Forensische Erkenntnisse
VirusTotal-Analyse
Wurden Sie von dieser Website betroffen?
Wenn Sie Kontoanmeldeinformationen, persönliche oder Zahlungsinformationen eingegeben oder eine Datei von dieser Domain heruntergeladen haben, ergreifen Sie sofort Maßnahmen. Nachfolgend finden Sie Ressourcen, die Ihnen helfen, den Vorfall zu melden und sich zu schützen.
Melden Sie sich bei Ihren örtlichen Behörden
Wählen Sie Ihr Land aus, um Offizielle Kontakte im Bereich Cyberkriminalität oder einen Beschwerdeentwurf erstellen → zu erhalten.
Jede beliebige Domain prüfen
Bedrohungsanalyse anhand gespeicherter Blocklisten, WHOIS, DNS und öffentlicher Scan-Beweise
Jetzt scannenPhishing melden
Melden Sie verdächtige Domains an unsere Bedrohungsdatenbank – schützen Sie die Community
MeldenEchtzeit-Bedrohungsfeed
Aktuelle Phishing-Meldungen und beobachtete Verfügbarkeitsänderungen
ÜberwachenBleiben Sie auf dem Laufenden, bleiben Sie sicher
Beobachten Sie aktuelle Bedrohungen oder legen Sie Widerspruch gegen diesen Eintrag ein, wenn Sie der Meinung sind, dass es sich um einen Fehlalarm handelt