# PhishDestroy threat dossier — trrzoire-suites.wasmer.app ================================================================ Fetched: 2026-07-03 22:03:59 UTC Canonical: https://phishdestroy.io/domain/trrzoire-suites.wasmer.app/ ## VERDICT ---------------------------------------------------------------- TAKEN DOWN (neutralised) Composite threat score: 59/100 (PhishDestroy scoring — see methodology below) Targeted brand: Trezor ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 2/91 security vendors flagged this domain Flagging vendors: Kaspersky, Netcraft Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 62.210.172.148 (FR, Paris) Hosting org: AS12876 Scaleway SAS Registrar: Wasmer Nameservers: alpha.ns.wasmernet.com, beta.ns.wasmernet.com Page title: Official Trezor™ Suite — Desktop & Web App for Hardware Wallets HTTP response: 410 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / YE2 Expires: 2026-09-13 Status: INVALID chain Fingerprint: 70742212f42b378a77cb11e7bdaee7467dff8bf38915ea7046e7241c7c4f3b4d ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: CLOSED — no report required. This domain was neutralised before the abuse-report cycle could be dispatched — either the hosting provider / registrar suspended it on their own, the DNS went dead, or the operator abandoned the infrastructure. PhishDestroy keeps the evidence bundle on file for audit but no formal notice was sent. ## TIMELINE ---------------------------------------------------------------- First detected: 2026-07-02 15:36:04 UTC (by PhishDestroy tracker) First reported: 2026-07-02 13:55:16 UTC (abuse notice filed) Last verified: 2026-07-03 20:20:36 UTC Neutralised: 2026-07-02 18:19:57 UTC Current status: taken down (registrar suspended or DNS dead) ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019f2309-faa4-730b-9986-0d3439ed4fb2/ URLQuery: https://urlquery.net/report/9c6b6c2a-340c-41d3-b2e4-2edecf8a4683 Wayback Machine: https://web.archive.org/web/*/trrzoire-suites.wasmer.app crt.sh CT logs: https://crt.sh/?q=%25.trrzoire-suites.wasmer.app Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=trrzoire-suites.wasmer.app AlienVault OTX: https://otx.alienvault.com/indicator/domain/trrzoire-suites.wasmer.app URLhaus: https://urlhaus.abuse.ch/host/trrzoire-suites.wasmer.app/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-02 15:45:53 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] This domain is flagged for brand_impersonation targeting Trezor, a well-known hardware wallet provider. The site presents itself as the official Trezor Suite application, using the page title 'Official Trezor™ Suite — Desktop & Web App for Hardware Wallets' to deceive users into believing it is a legitimate platform for managing cryptocurrency assets. Such impersonation is a common tactic to harvest sensitive credentials, including wallet recovery seeds, private keys, or login details, which can lead to unauthorized access and financial loss. The domain is designed to exploit trust in the Trezor brand, potentially targeting users seeking software updates or support for their hardware devices. Infrastructure analysis reveals that the domain trrzoire-suites.wasmer.app is currently active and registered through Wasmer, a platform often used for deploying web applications. The domain resolves to the IP address 62.210.172.148 and employs a Let's Encrypt SSL certificate, which provides encryption but does not validate legitimacy. As of the latest scan, VirusTotal reports 0 out of 95 security vendors flagging the domain, suggesting it has not yet been widely detected or blocked by security tools. This lack of detection may indicate recent deployment or evasion techniques designed to bypass automated analysis. No historical blocklist data is available, further emphasizing the domain's low visibility in threat intelligence feeds. Users who have visited trrzoire-suites.wasmer.app or interacted with its content should take immediate action to mitigate potential risks. First, disconnect any hardware wallets or devices that may have been connected to the site and avoid entering any credentials or sensitive information. If login details or recovery seeds were submitted, assume they are compromised and initiate account recovery procedures through the official Trezor channels. Monitor associated accounts for unauthorized transactions and consider revoking access to any connected applications or services. Additionally, report the domain to relevant security teams or platforms to aid in broader detection and takedown efforts. Users are advised to verify the authenticity of any Trezor-related websites by cross-referencing with official sources before engaging with them. ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260702-40C2C1 TLS cert SHA-256: 70742212f42b378a77cb11e7bdaee7467dff8bf38915ea7046e7241c7c4f3b4d ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/trrzoire-suites.wasmer.app/ JSON API: https://api.destroy.tools/v1/check?domain=trrzoire-suites.wasmer.app Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 174,416 domains (13,166 alive under monitoring, 160,432 confirmed takedowns/dead). Site: https://phishdestroy.io