trezor[.]io-start-suite[.]io
“Trezor Suite Web”
trezor.io-start-suite.io — सर्वर त्रुटि (HTTP 502). ब्रांड प्रतिरूपण: Trezor; घोटाले का प्रकार: Brand Impersonation. साक्ष्य सारांश: VirusTotal 3/91 (Fortinet, Gridinsoft, Kaspersky); URLScan malicious verdict; Spamhaus DBL_SPAM; PhishDestroy score 66/100. रजिस्ट्रार: NiceNIC.
मूल फॉरेंसिक रिकॉर्ड सुरक्षित रखने के लिए नीचे का विस्तृत PhishDestroy AI विश्लेषण अंग्रेज़ी में रखा गया है।
Analysis of the domain trezor.io-start-suite.io indicates it is a brand impersonation threat targeting Trezor, a cryptocurrency hardware wallet provider. The domain was registered on June 23, 2026, through NICENIC INTERNATIONAL GROUP CO., LIMITED, a registrar frequently associated with high-risk domains. Infrastructure analysis reveals the domain resolves to the IP address 2.27.1.18, hosted under AS210546 (CHSL ONE LTD) in Germany. Nameservers are configured to a.dnspod.com, b.dnspod.com, and c.dnspod.com, a pattern observed in other phishing campaigns leveraging DNSPod’s DNS services. The domain’s SSL certificate was issued by Let’s Encrypt (YR2), a common choice for both legitimate and malicious sites due to its free and automated issuance process.
Detection data shows the domain appears on one security blocklist, specifically PhishDestroy, and is flagged by 3 of 91 security vendors on VirusTotal, confirming its classification as malicious. Gridinsoft assigns a trust score of 0/100, further supporting its high-risk status. As of July 23, 2026, the domain is offline, though this does not preclude future reactivation or migration to a new infrastructure. The scam type is explicitly categorized as brand impersonation, with Trezor identified as the targeted brand.
No additional details about the exact content or functionality of the site are available, as the domain has not been actively crawled or analyzed for specific phishing mechanisms. Defenders should treat this domain as a confirmed threat and block it at the DNS, proxy, and endpoint levels. Monitoring for related domains registered through the same registrar or resolving to the same IP range is recommended to identify potential follow-up campaigns. Given the domain’s recent creation and rapid detection by security vendors, organizations should prioritize awareness for users handling cryptocurrency assets.
नेटवर्क सुरक्षा इंटेलिजेंस Registrar context
धमकी प्रतिक्रिया पाइपलाइन
सार्वजनिक ब्लॉकलिस्ट स्थिति
Latest Classified Outcome 2026-08-18 12:54:05 UTC
वायरसटोटल विश्लेषण
साक्ष्य और बाहरी रिपोर्टें
PD-20260624-6BD4C3 Recipient: abuse@chosting.solutions क्या आप इस साइट से प्रभावित हुए?
यदि आपने खाता क्रेडेंशियल, व्यक्तिगत या भुगतान जानकारी दर्ज की है, या इस डोमेन से कोई फ़ाइल डाउनलोड की है, तो तुरंत कार्रवाई करें। घटना की रिपोर्ट करने और अपनी सुरक्षा करने में आपकी सहायता के लिए नीचे संसाधन दिए गए हैं।
अपने स्थानीय अधिकारियों को रिपोर्ट करें
आधिकारिक साइबर अपराध संपर्क, या एक शिकायत ड्राफ्ट बनाएं → प्राप्त करने के लिए अपना देश चुनें।
किसी भी डोमेन की जाँच करें
संग्रहीत ब्लॉकलिस्ट, WHOIS, DNS और सार्वजनिक स्कैन साक्ष्य का उपयोग करके खतरे का विश्लेषण
अभी स्कैन करेंफ़िशिंग की रिपोर्ट करें
संदिग्ध डोमेन हमारे थ्रेट डेटाबेस में जमा करें — समुदाय की सुरक्षा करें
रिपोर्ट करेंसीधा खतरा फीड
हाल की फ़िशिंग रिपोर्टें और उपलब्धता में परिवर्तन देखे गए
निगरानी करेंजानकारी में रहें, सुरक्षित रहें
लाइव खतरों की निगरानी करें या यदि आपको लगता है कि यह एक गलत सकारात्मक है तो इस लिस्टिंग को चुनौती दें।