trezior-hardware-live[.]vercel[.]app
“Trézor.io/Start® | Starting Up Your Device - Trézor®”
trezior-hardware-live.vercel.app — Contenu indisponible. Usurpation de l'identité de la marque : Trezor; Type d'arnaque : Crypto Scam. Résumé des preuves: VirusTotal 15/95 (ADMINUSLabs, Criminal IP, alphaMountain.ai, BitDefender, CyRadar); URLScan malicious verdict; CF Radar malicious; PhishDestroy score 95/100. Bureau d’enregistrement: Vercel.
L’analyse détaillée de PhishDestroy AI reste en anglais afin de préserver le relevé forensique original.
Analysis of trezior-hardware-live.vercel.app as of July 25, 2026 shows that the site was used to impersonate the hardware‑wallet brand Trezor. The page title returned by the server, “Trézor.io/Start® | Starting Up Your Device - Trézor®”, directly references the legitimate Trezor brand, confirming a brand‑impersonation tactic. The domain is hosted on Vercel infrastructure and serves content over HTTPS with a Google Trust Services / WR1 certificate, indicating a valid TLS chain but offering no assurance of legitimacy. HTTP response code 451 signals that the content was unavailable due to legal reasons, consistent with the reported “taken offline” status. DNS resolution points to IP 64.29.17.67, which belongs to Amazon.com, Inc. (AS16509) in the United States, a common hosting provider for disposable phishing sites.
The site employed HSTS, a standard security header, but this does not mitigate the underlying impersonation. VirusTotal scans flagged the domain by 15 of 95 security vendors, and the domain appears on at least one external blocklist, confirming that multiple security engines consider it malicious. PhishDestroy has also listed the site as blocked. The registrar information shows the domain was registered through Vercel Inc., a platform that allows rapid deployment of short‑lived domains.
No nameserver data were returned, and the domain is currently offline, limiting immediate observation of payloads. Defenders should continue to block the domain at network and email gateways, ensure that any URL filtering solutions reference the observed blocklist entries, and monitor for additional domains that use the same Vercel‑based deployment pattern targeting Trezor users. Threat intelligence feeds should be updated with the observed indicators—domain name, IP address, SSL certificate fingerprint, and HTTP 451 response—to support rapid detection of re‑hosted copies.
Renseignements sur la sécurité réseau
Processus de réponse aux menaces Pipeline
Statut de la liste de blocage publique
Technologies · 2 identified
Vercel is a cloud platform for static frontends and serverless functions.
vercel.com Confiance à 100 %HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org Confiance à 100 %Analyse VirusTotal
Preuves archivées
Données factuelles et rapports externes
Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif