trezor-data[.]gxtigroup[.]com
“Index of /”
Résumé des preuves
The domain trezor-data.gxtigroup.com was observed being used in a brand‑impersonation campaign targeting the cryptocurrency hardware wallet provider Trezor. VirusTotal records show that 11 of 93 scanned security vendors flagged the domain as malicious, indicating a moderate level of detection across the ecosystem. The site was registered on 21 February 2026 and, at the time of analysis (23 July 2026), the host has taken the service offline. PhishDestroy listed the domain on its blocklist, and the domain also appears on a single external security blocklist, reinforcing the view that it was actively being used for malicious purposes.
The SSL certificate presented is identified as “R12”, a detail that aligns with typical short‑lived certificates used by transient phishing infrastructure. Gridinsoft assigned a trust score of 0 out of 100, the lowest possible rating, further confirming the domain’s lack of legitimacy. The HTTP response returned the generic page title “Index of /”, which provides no functional content but is consistent with a placeholder page often employed to hide malicious payloads. The campaign has been classified as a crypto‑scam, and the domain explicitly impersonates the Trezor brand, suggesting that victims may have been directed to submit wallet credentials or seed phrases.
Because the hosting IP, registrar, and ASN information were not disclosed in the available intelligence, the full infrastructure footprint remains partially unknown. Defenders should ensure that the domain is added to DNS and URL filtering blocklists, monitor for any residual traffic to the associated IP ranges, and update incident response playbooks to include Trezor‑related impersonation indicators. Continuous re‑evaluation is advised in case the domain is re‑hosted or the underlying infrastructure is reused in future campaigns.
Data Coverage
Processus de réponse aux menaces Pipeline
Couverture des listes de blocage
10 sources externes surveillées · instantané du 11/08/2026
10 sources externes surveillées Aucune correspondance
Analyse forensique
Analyse VirusTotal
Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif