trezor[.]io-app[.]online
“Trezor Suite App (Official) | The Secure Hub for All Your Digital Assets”
trezor.io-app.online — Contenido no disponible (HTTP 502). Suplantación de marca: Trezor; Tipo de estafa: Crypto Scam. Resumen de las pruebas: VirusTotal 12/93 (alphaMountain.ai, BitDefender, CyRadar, ESET, Fortinet); PhishDestroy score 86/100.
El análisis detallado de PhishDestroy AI se mantiene en inglés para conservar el registro forense original.
On 25 July 2026, the domain trezor.io-app.online was observed hosting a brand‑impersonation page that claimed to be the “Trezor Suite App (Official)”. The site was registered on 21 February 2026 and resolved to the IPv4 address 66.33.60.129, which is allocated to Amazon.com, Inc. (AS16509) in the United States. VirusTotal recorded 12 detections out of 93 scanning engines, indicating that a minority of security products flagged the domain as malicious. The SSL certificate was identified with the rating “R10”, and the Gridinsoft trust score was 0 / 100, reflecting a lack of trustworthiness.
The domain was listed on a single security blocklist and was actively taken down by the PhishDestroy mitigation service; its current HTTP status is offline. The page title explicitly references the Trezor brand, confirming the impersonation of the hardware‑wallet provider. The campaign is classified as a crypto‑scam, consistent with the use of the Trezor brand to lure cryptocurrency users. Defenders should immediately add 66.33.60.129 to deny‑list rules, enforce DNS filtering for the trezor.io‑app.online suffix, and monitor for newly registered domains that combine the “trezor” keyword with the “io‑app.online” TLD pattern.
Network‑level controls should include blocking traffic to the identified ASN (AS16509) when it originates from suspicious URLs. Threat‑intel feeds should be updated to reflect the 12 VirusTotal detections and the 0 / 100 Gridinsoft score, and security appliances should be instructed to treat any future resolution of this domain as malicious. Continuous review of phishing‑related blocklists is advised, as the low blocklist count suggests that broader community awareness may still be limited.
Proceso de respuesta ante amenazas Pipeline
Estado de la lista de bloqueados pública
Inteligencia forense
Análisis de VirusTotal
Datos y informes externos
¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.