Notification and current-status evidence
The sent-report ledger records the first outgoing report at . A report was sent to the recorded registrar; contact details remain in Domain Intelligence. The latest stored availability evidence still shows the domain reachable; 6 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
trezoriostart[.]stormkit[.]dev
“Trezor.io/Start | Starting Up Your® Device”
Résumé des preuves
This domain, trezoriostart.stormkit.dev, poses a brand impersonation threat targeting users of Trezor, a hardware cryptocurrency wallet. The site presents itself as the official Trezor setup page, titled "Trezor.io/Start | Starting Up Your® Device," with the intent to deceive users into entering sensitive information such as recovery seeds, private keys, or wallet credentials. If successful, attackers could gain unauthorized access to victims' cryptocurrency holdings, leading to potential financial loss or complete account compromise. The site is designed to closely resemble Trezor’s legitimate interface, making it difficult for users to distinguish between the real and fraudulent pages without careful inspection. Analysis indicates this domain was created on February 21, 2026, and registered through GoDaddy.com, LLC. It resolves to the IP address 91.98.218.209, hosted on infrastructure belonging to Hetzner Online GmbH (AS24940) in Germany. The domain is flagged by 17 out of 95 security vendors on VirusTotal, and it appears on at least one security blocklist. The SSL certificate is issued by Let’s Encrypt, a common practice among both legitimate and malicious sites to appear trustworthy. The use of a subdomain under stormkit.dev, a platform typically associated with web application hosting, suggests an attempt to leverage a legitimate service to evade detection and lend credibility to the phishing infrastructure. If you visited trezoriostart.stormkit.dev or interacted with its content, immediate action is required to mitigate potential risks. First, disconnect any devices that were connected to the site and avoid entering any further information. If you provided sensitive data such as a recovery seed or private key, treat your Trezor wallet as compromised and transfer any remaining funds to a new, secure wallet using a different recovery seed. Monitor your cryptocurrency accounts for unauthorized transactions and enable additional security measures, such as multi-factor authentication, where available. Report the incident to Trezor’s official support channels and consider notifying relevant cybersecurity organizations to aid in tracking and takedown efforts. Regularly update your security software and remain vigilant for similar phishing attempts targeting cryptocurrency users.
Instantané des preuves transmises
- Envoyé
- Entrées du registre
- 1
- ID du dossier
PD-20260203-AF8ECB- Titre de la page capturée
- Trezor.io/Start | Starting Up Your® Device
- Artefact PDF
- Preuve PDF
Fondement juridique
Texte intégral des preuves
Acceptable Use Policy (AUP): The domain trezoriostart.stormkit.dev is engaged in phishing activities, which constitutes a clear violation of your AUP prohibiting illegal activities, fraud, and deception.
Terms of Service (TOS): The use of this domain for phishing purposes violates your TOS, which reserves the right to suspend or terminate services for any activities that contravene legal standards or your policies.
Applicable Laws (Unknown):
Computer Fraud and Abuse Act (CFAA): This U.S. law prohibits unauthorized access to computers and the fraudulent use of information obtained, which applies to phishing schemes.
Wire Fraud Statute (18 U.S.C. § 1343): This law criminalizes schemes to defraud individuals or entities using electronic communications, which is pertinent to the activities associated with this domain.
Anti-Phishing Act (15 U.S.C. § 7704): This act specifically addresses the illegal use of misleading information to deceive individuals into providing personal information, directly applicable to the domain in question.
Regulatory Note: Failure to take immediate action against this domain may expose your organization to liability under applicable laws and could result in regulatory scrutiny. Prompt compliance is essential to mitigate potential legal repercussions.
Data Coverage
Renseignements sur la sécurité réseau
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Cloudflare DNS | trezoriostart.stormkit.dev |
malicious | Sinkholed |
| OpenDNS | trezoriostart.stormkit.dev |
phishing | Phishing Block |
| Hagezi Threat Feed | trezoriostart.stormkit.dev |
malicious | Sinkholed |
| DNS4EU | trezoriostart.stormkit.dev |
malicious | Sinkholed |
Processus de réponse aux menaces Pipeline
Couverture des listes de blocage
10 sources externes surveillées · instantané du 13/08/2026
10 sources externes surveillées Aucune correspondance
Chronologie de détection
-
État du domaine
Accessible → Inaccessible
-
Cloudflare Radar
Analyse Cloudflare Radar enregistrée · Ouvrir l’analyse
-
État du domaine
Inaccessible → Accessible
Capture enregistrée
Informations sur les domaines
Détails techniquesDNS, noms TLS et horodatages
ICANN OVERSIGHT
Registration: stormkit.dev
Contexte de l’accréditation et du RAA
Contexte de l’accréditation et du RAA
Registrar accreditation and DNS abuse obligations
For the registrable domain stormkit.dev behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Technologies
1 technologie identifiée avec une forte confiance
Analyse VirusTotal
Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif