Skip to security report
⚠️
This domain has been flagged as malicious
Security engines reporting a detection: 20. Exercise extreme caution — do not enter credentials or personal information.
Domain security and threat intelligence

started-trezo[.]zapier[.]app

“Trezor Start® — Trezor®”

Threat verdict Critical 95/100 evidence score
Availability Content unavailable Content was unavailable in the latest observation
VirusTotal detections: 20/93 URLQuery threat systems: 4 alerts Brand impersonation: Trezor
Feb 26, 2026 Trezor 1 Report Sent CDN
Evidence Summary
CRITICAL
Ref
A78B9163
Score
95/100

This domain is flagged as an elevated-risk brand impersonation threat targeting Trezor, a cryptocurrency hardware wallet provider. The page title 'Trezor.io/start' directly mimics the legitimate Trezor onboarding process, indicating an intent to deceive users into disclosing sensitive credentials or installing malicious software under the guise of a trusted brand. Analysis indicates the domain started-trezo.zapier.app was registered on February 26, 2026, through Name.com, Inc. and resolves to IP address 64.239.109.193, hosted on Amazon.com, Inc. infrastructure (AS16509). It appears on one security blocklist and is blocked by at least one threat intelligence feed. VirusTotal reports 19 out of 95 security vendors flagging the domain as malicious. The SSL certificate is issued by Let's Encrypt (R12), a common choice for both legitimate and malicious domains due to its free and automated issuance process. Mitigation steps for this threat type include blocking the domain and its resolving IP at network perimeter controls. Organizations should update endpoint protection rules to detect and prevent access to brand-impersonation domains, particularly those mimicking cryptocurrency services. Users should be trained to verify domain authenticity by cross-referencing URLs with official sources and avoiding interaction with unsolicited links. Incident response teams should monitor for credential theft or unauthorized transactions following exposure to this domain, as it aligns with common attack patterns targeting cryptocurrency users.

VirusTotal
VirusTotal
20 det.
URLQuery
URLQuery
4 threat alerts
CF Radar
Malicious
URLScan
URLScan
TLS Certificate
Expired or unverified -94d
Age
6 mo
Observed status
Content unavailable
PhishDestroy
DestroyList
Listed
Reports Sent
1
Data coverage VirusTotal 20 / 93 URLQuery 4 threat-system alerts PhishStats checked — no match recorded OTX no community references CF Radar provider verdict: malicious URLScan capture stored report URLScan verdict malicious DNS blocks not checked TLS Expired or unverified WHOIS 6 mo old Screenshot 3 captures · 3 sources Redirect chain not probed
Network Security Intelligence
Threat Detection Systems 4 alerts
Detection System Indicator Verdict Alert
OpenDNS started-trezo.zapier.app phishing Phishing Block
Hagezi Threat Feed started-trezo.zapier.app malicious Sinkholed
Cloudflare DNS started-trezo.zapier.app malicious Sinkholed
DNS4EU started-trezo.zapier.app malicious Sinkholed
CF Cloudflare Radar Verdict Malicious
Phishing Security threats Phishing

Threat Response Pipeline

Discovery
Checks
Reports
Availability
19/19
Sent Report Recorded
Stored sent-report record for registrar Name.com, Inc., hosting provider, 2 abuse contacts
abuse@name.comabuse@vercel.com
Feb 26, 2026

Public Blocklist Status

Stored Capture

Page Title
Trezor Start® — Trezor®
Impersonates
Ethereum Trezor
TLS Certificate
Expired or unverified · Issued by Let's Encrypt / R12

Domain Intelligence

Domain
URLScan Verdict Malicious score 100 Phishing brand: Trezor report ↗
Server / ASN Vercel · AS16509 AMAZON-02 - Amazon.com, Inc., US
IP Context Vercel shared edge origin IP hidden Edge-IP reputation is not attributed to this domain.
Registrar (base domain) Name.com US(US)
IP Address 64.239.123.193 CDN
GeoUS Walnut, US
NetworkAS16509 · Amazon.com, Inc.
The origin IP is hidden behind a CDN proxy. Reverse-IP results for the edge address contain unrelated tenants; finding the origin requires passive DNS or certificate-transparency data.
Registration (base domain)zapier.app · Created Feb 26, 2026 (170d) Expires Sep 21, 2026
Time to First Unavailability 17 days
What we count Elapsed time from the first stored abuse report to the first observation that the content was unavailable. This does not establish the cause.
What each report contains Stored outgoing-report records may reference evidence available at the time, such as vendor verdicts, registration data, hosting details, classifications, or screenshots. This page does not infer the exact payload delivered, receipt, acknowledgement, or action by a recipient.
Technical detailsDNS, SSL SANs, timestamps
First DetectedFeb 26, 2026
DOM Analysisanalyzed Jul 29, 2026score 0/1002 brand signals
IoC Extractionscanned Aug 2, 20260 wallet · 0 Telegram IoCs
Submitted URLhttps://started-trezo.zapier.app/start
Nameserversns2.vercel-dns.com
TLS Fingerprint
TLS Observationvalid from Feb 14, 2026scanned Mar 15, 2026
Favicon Hash
Case ID
ICANN OVERSIGHT Registration: zapier.app

Accreditation and RAA context

Registrar accreditation and DNS abuse obligations

For the registrable domain zapier.app behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.

Accreditation is a contract, not a safety certification.

RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.

Accountability draft Nothing is sent automatically.
Technologies · 6 identified
Amazon Web Services
PaaS

Amazon Web Services (AWS) is a comprehensive cloud services platform offering compute power, database storage, content delivery and other functionality.

aws.amazon.com 100% confidence
Vercel
PaaS

Vercel is a cloud platform for static frontends and serverless functions.

vercel.com 100% confidence
Stripe
Payment processors

Stripe offers online payment processing for internet businesses as well as fraud prevention, invoicing and subscription management.

stripe.com 100% confidence
reCAPTCHA
Security

reCAPTCHA is a free service from Google that helps protect websites from spam and abuse.

www.google.com 100% confidence
HSTS
Security

HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.

www.rfc-editor.org 100% confidence
Amazon S3
CDN

Amazon S3 or Amazon Simple Storage Service is a service offered by Amazon Web Services (AWS) that provides object storage through a web service interface.

aws.amazon.com 100% confidence
Detected via Cloudflare Radar · Wappalyzer engine
Report This Domain Submit evidence & help protect others

VirusTotal Analysis

20 / 93 security vendors flagged this domain
View on VT
Last analyzed
ADMINUSLabs
alphaMountain.ai
Cluster25
CRDF
CyRadar
DNS8
ESET
Emsisoft
Forcepoint ThreatSeeker
Fortinet
G-Data
Gridinsoft
Kaspersky
Lionic
Netcraft
PhishFort
Sophos
Trustwave
VIPRE
Webroot

Archived Evidence

Wayback Machine Snapshot
A historical snapshot is available for evidence review
View Archive
Site Performance Analysis

Google PageSpeed Insights — mobile performance audit of started-trezo.zapier.app · checked Mar 2, 2026

39
Poor
Performance
FCP
2.79s
First Contentful Paint
LCP
13.03s
Largest Contentful Paint
CLS
0
Cumulative Layout Shift
TBT
2509ms
Total Blocking Time
SI
4.58s
Speed Index
Powered by Google PageSpeed Insights · Mobile strategy · Scores: 90-100 Good 50-89 Needs Work 0-49 Poor
Site Configuration Analysis
Stored observations are retained with their original collection time.
robots.txt Present · HTTP 200
Valid robots.txt; no Disallow/Allow paths were extracted.
Sitemap 1 page · HTTP 200

Evidence & External Reports

Third-Party Detection — ChainAbuse
2 reports filed for started-trezo.zapier.app · category: Phishing · source checked
Flagged by Anti-Phishing Volunteers & Associates on Feb 28, 2026 — automated submission, not a user testimony. Source: ChainAbuse (TRM Labs).
Submitted Evidence Snapshot
Sent: Ledger records: 1 Case ID: PD-20260226-520F9E Recipient: abuse@name.com
Page title stored with report: Trezor Start® — Trezor®
URLScan evidence VirusTotal evidence URLQuery evidence Screenshot 48.3 KB

Were You Affected by This Site?

If credentials were compromised, report immediately. Do not engage with recovery scammers.

If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.

Europol
Find the official reporting channel for your EU country
National police directory
Beware of recovery scammers! Recovery scammers may pose as investigators, lawyers, or tracing services. Do not pay upfront fees or disclose credentials. Learn more about recovery fraud →

Report to Your Local Authorities

Select your country to get official cybercrime contacts, or create a complaint draft →.

97-country directory
Template-based draft • optional AI wording assistance requires separate consent Review and submit it yourself

Check Any Domain

Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence

Scan Now

Report Phishing

Submit suspicious domains to our threat database — protect the community

Report

Live Threat Feed

Recent phishing reports and observed availability changes

Monitor

Stay Informed, Stay Safe

Monitor live threats or contest this listing if you believe it's a false positive

Live Threat Feed Appeal This Listing
HTML · IFRAME

Embed This Report

Share this threat intelligence on your website or blog

embed.html
<iframe
  src="https://phishdestroy.io/embed/domain/started-trezo.zapier.app"
  title="PhishDestroy threat report for started-trezo.zapier.app"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>

A Very Sincere Thank-You Note

Satirical draft generator

Recipient
Fee context

Satirical draft. Fee figures are estimates; exact attribution to this domain is not claimed.