MALICIOUS — CRITICAL
Trezor.com.im Brand Impersonation Warning
trezor[.]
Analysis of the domain trezor.com.im shows it was registered on 2026-06-08 and currently resolves to the IPv4 address 156.226.126.21, hosted in Hong Kong by CloudFly Net Inc.
- VirusTotal
- 19/91
- Blocklists
- 2 · MetaMask, SEAL
- Ketersediaan
- Terakhir diketahui aktif · HTTP 200
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
trezor.com.im — Terakhir diketahui aktif (HTTP 200). Peniruan identitas merek: Trezor; Jenis penipuan: Brand Impersonation. Ringkasan bukti: VirusTotal 19/91 (ADMINUSLabs, ChainPatrol, alphaMountain.ai, BitDefender, Chong Lua Dao); Spamhaus DBL_PHISH; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 100/100.
Analisis terperinci PhishDestroy AI di bawah tetap berbahasa Inggris untuk menjaga catatan forensik asli.
Evidence Analysis
Analysis of the domain trezor.com.im shows it was registered on 2026-06-08 and currently resolves to the IPv4 address 156.226.126.21, hosted in Hong Kong by CloudFly Net Inc. The site presents a valid TLS certificate issued by Let’s Encrypt (R12), and HTTP requests return status code 200. The page title returned by the server is a garbled string containing “Trezor” and Chinese characters, indicating an attempt to masquerade as the official Trezor brand. VirusTotal records indicate that 18 of 91 scanners flag the domain, and the domain appears in four AlienVault OTX pulses and three independent blocklists. It is actively blocked by PhishDestroy, MetaMask, and SEAL, and receives a Gridinsoft trust score of 0 / 100, reinforcing its malicious classification as a high‑risk brand‑impersonation campaign targeting Trezor users. The evidence confirms active infrastructure but provides no additional details on the phishing page content or credential collection mechanisms. Defenders should add the domain and its resolving IP to blocklists, enforce TLS inspection, and monitor for related traffic, while threat‑intel teams may query the associated blocklists for indicators of compromise and investigate any observed connections to the HK host.
Stored source results
Recorded verdicts and infrastructure observations for this domain.
Cakupan data12 recorded checks
Alur Tanggapan Ancaman Pipeline
Status Daftar Blokir Publik
Intelijen Domain
Rincian teknisDNS, SAN SSL, cap waktu
Analisis VirusTotal
Bukti & Laporan EksternalIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Jika Anda memasukkan kredensial akun, informasi pribadi atau pembayaran, atau mengunduh file dari domain ini, segera ambil tindakan. Di bawah ini adalah sumber daya untuk membantu Anda melaporkan insiden tersebut dan melindungi diri Anda sendiri.
Laporkan kepada Pihak Berwenang di Daerah Anda
Pilih negara Anda untuk mendapatkan kontak resmi kejahatan dunia maya, atau membuat draf pengaduan →.