app-trezor-com[.]pro
Résumé des preuves
The domain app-trezor-com.pro is confirmed as a brand impersonation phishing site targeting users of Trezor, a cryptocurrency hardware wallet provider. Analysis indicates the domain was designed to deceive victims into believing they were interacting with legitimate Trezor services. The site is currently offline, though prior activity warrants further scrutiny. Infrastructure analysis reveals the domain was registered through NICENIC INTERNATIONAL GROUP CO., LIMITED on March 17, 2026, and resolved to the IP address 172.67.181.121. Security vendors flagged the domain in 16 of 95 VirusTotal scans, while Gridinsoft assigned a trust score of 0/100. The site appeared on one security blocklist and employed Cloudflare services, including Cloudflare Browser Insights and HTTP/3, likely to obfuscate its origin. The SSL certificate was issued by Let's Encrypt, a common tactic to lend superficial legitimacy to phishing infrastructure. The domain has been taken offline, but organizations should remain vigilant. Network defenders are advised to block the domain and associated IP address at perimeter security controls. Cryptocurrency service providers and users should monitor for similar impersonation attempts, particularly those leveraging Cloudflare or Let's Encrypt certificates. If historical access logs exist, review for interactions with this domain to assess potential exposure or compromise.
Data Coverage
Renseignements sur la sécurité réseau
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| OpenDNS | app-trezor-com.pro |
phishing | Phishing Block |
| Hagezi Threat Feed | app-trezor-com.pro |
malicious | Sinkholed |
| DNS4EU | app-trezor-com.pro |
malicious | Sinkholed |
Processus de réponse aux menaces Pipeline
Couverture des listes de blocage
10 sources externes surveillées · instantané du 12/08/2026
10 sources externes surveillées Aucune correspondance
Preuves du résultat enregistrées
Résultat et attribution du retrait
- Résultat
protected- Disponibilité
reachable_protected- Cause
cloudflare_challenge- Acteur
- Cloudflare
- Mécanisme
challenge- Confiance
- 85%
- Première observation
- Dernière observation
SHA-256 de la preuve 0ffb358c5791
Chronologie de détection
-
VirusTotal
0 → 8
-
VirusTotal
8 → 16
-
Disponibilité
Première valeur enregistrée : Inconnu
993d00c35140 -
Disponibilité
Inconnu → Protégé
985c9a0958dd -
Disponibilité
Protégé → Inconnu
576744427e6f -
Disponibilité
Inconnu → Protégé
fb99bb7df85c -
Disponibilité
Protégé → Inconnu
7cebcfd4071c -
Disponibilité
Inconnu → Protégé
eddf45e5b2e4 -
Disponibilité
Protégé → Inconnu
ca255b61650a -
Disponibilité
Inconnu → Protégé
37a73119603e
Tout afficher (4)
-
Disponibilité
Protégé → Inconnu
d8f7d37d7f95 -
Disponibilité
Inconnu → Protégé
607d59f40e67 -
Disponibilité
Protégé → Inconnu
afa49a2b04dd -
Disponibilité
Inconnu → Protégé
0ffb358c5791
Signalements communautaires
Signalé par 1 membre de la communauté ; première observation le 23/03/2026
- Signalements enregistrés
- 1
- URL signalées uniques
- 1
Capture enregistrée
Informations sur les domaines
Détails techniquesDNS, noms TLS et horodatages
ICANN OVERSIGHT
Contexte de l’accréditation et du RAA
Contexte de l’accréditation et du RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Analyse VirusTotal
Analyse des performances du site
Google PageSpeed Insights — mobile performance audit of app-trezor-com.pro · checked Jun 26, 2026
Domaines ressemblants
74 domaines ressemblants enregistrés
Tout afficher (62)
Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif