faq-public-trzor-io-cdn[.]typedream[.]app
“Trezor.io/Start® | Trezor Suite App (Official) | Trezor®”
faq-public-trzor-io-cdn.typedream.app — Contenuto non disponibile. Simulazione del marchio: Trezor; Tipo di truffa: Seed Phrase Theft. Riepilogo delle prove: VirusTotal 14/91 (ChainPatrol, alphaMountain.ai, BitDefender, CyRadar, ESET); URLScan malicious verdict; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 92/100. Registrar: Typedream.
L’analisi dettagliata di PhishDestroy AI resta in inglese per preservare il rapporto forense originale.
This assessment examines the domain faq-public-trzor-io-cdn.typedream.app, which is currently active and poses a high-risk brand impersonation threat. The domain is designed to mimic the Trezor brand, leveraging a page title that directly references the legitimate Trezor suite and onboarding process. The infrastructure is hosted via Typedream, a no-code platform, suggesting ease of deployment for threat actors. The domain's presentation and branding aim to deceive users into believing they are interacting with an official resource, a common tactic in credential theft and cryptocurrency drainer operations, although no specific drainer kit is identified in this instance.
Technical analysis reveals multiple concrete indicators of compromise. VirusTotal reports that 2 out of 95 security vendors have flagged this domain, highlighting the presence of threat intelligence but also a potential gap in broader detection coverage. The domain resolves to IP address 188.114.96.3, which is associated with cloud-based hosting infrastructure. It is registered through Typedream, a platform facilitating rapid domain deployment. The SSL certificate is provided by Google Trust Services, giving the appearance of legitimacy through HTTPS encryption. No specific blocklist or Google Safe Browsing (GSB) status is provided, but the VirusTotal score and active status indicate ongoing risk exposure.
The domain remains live and accessible at the time of analysis, presenting an immediate threat to users seeking official Trezor information or downloads. The impersonation tactics, technical infrastructure, and partial detection by threat intelligence platforms warrant urgent mitigation, including browser-level blocking, user awareness campaigns, and reporting to relevant security authorities. Until the domain is taken down or fully blocked by major security solutions, there is a significant risk of user credential or asset theft. Users are strongly advised to avoid interacting with the domain and to verify sources through official channels.
Pipeline di risposta alle minacce
Stato della lista di blocco pubblica
Tecnologie · 11 identified
Node.js is an open-source, cross-platform, JavaScript runtime environment that executes JavaScript code outside a web browser.
nodejs.org Confidenza al 100%React is an open-source JavaScript library for building user interfaces or UI components.
reactjs.org Confidenza al 100%Next.js is a React framework for developing single page Javascript applications.
nextjs.org Confidenza al 100%Google Cloud Trace is a distributed tracing system that collects latency data from applications and displays it in the Google Cloud Console.
cloud.google.com Confidenza al 100%Cloud CDN uses Google's global edge network to serve content closer to users.
cloud.google.com Confidenza al 100%Cloudflare Browser Insights is a tool that measures the performance of websites from the perspective of users.
www.cloudflare.com Confidenza al 100%Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com Confidenza al 100%HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org Confidenza al 100%Analisi di VirusTotal
Analisi delle prestazioni del sito
Google PageSpeed Insights — mobile performance audit of faq-public-trzor-io-cdn.typedream.app · checked Jun 29, 2026
Dati e relazioni esterne
Questo sito ti ha influenzato in qualche modo?
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.
Verifica qualsiasi dominio
Analisi delle minacce utilizzando blocklist archiviate, WHOIS, DNS e prove di scansione pubblica
Scansiona oraSegnala un tentativo di phishing
Segnala i domini sospetti al nostro database delle minacce — proteggi la comunità
SegnalaFeed in tempo reale sulle minacce
Segnalazioni recenti di phishing e modifiche osservate della disponibilità
MonitoraRimani informato, rimani al sicuro
Controlla le minacce in tempo reale oppure contesta questa segnalazione se ritieni che si tratti di un falso positivo