# PhishDestroy threat dossier — wel-trezor-login-feq.typedream.app ================================================================ Fetched: 2026-07-24 10:20:14 UTC Canonical: https://phishdestroy.io/domain/wel-trezor-login-feq.typedream.app/ ## VERDICT ---------------------------------------------------------------- ACTIVE + CLOAKED — returns HTTP 666 to scanners, real fraudulent site to victims Composite threat score: 100/100 (PhishDestroy scoring — see methodology below) Targeted brand: Trezor Cloaking: DETECTED — domain returns custom HTTP 666 to scanners while serving fraudulent content to real users (type: content_divergence) (score: 2/6) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 9/91 security vendors flagged this domain Flagging vendors: ChainPatrol, alphaMountain.ai, BitDefender, CyRadar, Fortinet, G-Data, Kaspersky, PhishFort, Sophos Public blocklists: listed on 3 independent blocklists ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 188.114.96.3 (US, San Francisco) ASN: ASAS13335 CLOUDFLARENET - Cloudflare, Inc., US Hosting org: AS13335 Cloudflare, Inc. Registrar: Typedream Nameservers: NS_NOT_FOUND Page title: Trezor Suite - Get Your All Digital Assets in One Wallet HTTP response: 403 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Google Trust Services / WE1 Expires: 2026-08-26 Status: INVALID chain Fingerprint: 7cbc9d5acaff550ef5d29c76a71bdf4aac8fd42efa8207719f76b60ff6ed4b81 Subject Alternative Names (related infrastructure — often same operator): - typedream.app ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- First detected: 2026-06-29 16:27:54 UTC (by PhishDestroy tracker) Last verified: 2026-07-24 08:20:27 UTC Neutralised: 2026-06-29 18:17:40 UTC Current status: ACTIVE — cloaked behind HTTP 666 to evade scanners ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019f13c6-1525-7516-96d9-db72a97b412b/ Wayback Machine: https://web.archive.org/web/*/wel-trezor-login-feq.typedream.app crt.sh CT logs: https://crt.sh/?q=%25.wel-trezor-login-feq.typedream.app Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=wel-trezor-login-feq.typedream.app AlienVault OTX: https://otx.alienvault.com/indicator/domain/wel-trezor-login-feq.typedream.app URLhaus: https://urlhaus.abuse.ch/host/wel-trezor-login-feq.typedream.app/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-06-29 18:00:33 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] wel-trezor-login-feq.typedream.app Fake Trezor Crypto Drainer This domain, wel-trezor-login-feq.typedream.app, operates as a crypto drainer infrastructure designed to impersonate Trezor Suite, a legitimate cryptocurrency wallet platform. The site presents a fraudulent interface mimicking Trezor’s official login portal, aiming to deceive users into entering wallet credentials or connecting their wallets directly. Once compromised, the attacker can execute unauthorized transactions, draining digital assets from the victim’s wallet. The threat specifically targets users of hardware and software wallets, exploiting trust in the Trezor brand to facilitate financial theft. Analysis of the domain reveals it currently resolves to IP address 188.114.96.3 and remains active despite zero detections out of 95 security engines on VirusTotal. The domain was registered through Typedream, a platform that enables rapid deployment of web pages without extensive verification. No blocklist entries or prior malicious associations have been recorded for this domain at the time of investigation. The page title, 'Trezor Suite - Get Your All Digital Assets in One Wallet,' directly mirrors official Trezor branding, increasing the likelihood of successful social engineering. Users who have visited this domain or interacted with its content should immediately disconnect any connected wallets and revoke access via their wallet’s connected sites or dApp permissions. It is critical to audit recent transactions for unauthorized activity and transfer remaining assets to a new, secure wallet. No credentials or recovery phrases should ever be entered on untrusted sites, regardless of visual resemblance to legitimate services. Monitoring for further indicators of compromise, such as unexpected transaction confirmations or wallet disconnections, is strongly advised. If financial loss has occurred, reporting the incident to relevant blockchain analytics services and law enforcement may aid in tracking the stolen assets. [Updates since narrative was generated:] - Public blocklists: now listed on 3 feeds ## EVIDENCE HASHES ---------------------------------------------------------------- TLS cert SHA-256: 7cbc9d5acaff550ef5d29c76a71bdf4aac8fd42efa8207719f76b60ff6ed4b81 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/wel-trezor-login-feq.typedream.app/ JSON API: https://api.destroy.tools/v1/check?domain=wel-trezor-login-feq.typedream.app Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 189,173 domains (58,515 alive under monitoring, 129,042 confirmed takedowns/dead). Site: https://phishdestroy.io