trezior-hardware-live[.]vercel[.]app
“Trézor.io/Start® | Starting Up Your Device - Trézor®”
trezior-hardware-live.vercel.app — Contenuto non disponibile. Simulazione del marchio: Trezor; Tipo di truffa: Crypto Scam. Riepilogo delle prove: VirusTotal 15/95 (ADMINUSLabs, Criminal IP, alphaMountain.ai, BitDefender, CyRadar); URLScan malicious verdict; CF Radar malicious; PhishDestroy score 95/100. Registrar: Vercel.
L’analisi dettagliata di PhishDestroy AI resta in inglese per preservare il rapporto forense originale.
Analysis of trezior-hardware-live.vercel.app as of July 25, 2026 shows that the site was used to impersonate the hardware‑wallet brand Trezor. The page title returned by the server, “Trézor.io/Start® | Starting Up Your Device - Trézor®”, directly references the legitimate Trezor brand, confirming a brand‑impersonation tactic. The domain is hosted on Vercel infrastructure and serves content over HTTPS with a Google Trust Services / WR1 certificate, indicating a valid TLS chain but offering no assurance of legitimacy. HTTP response code 451 signals that the content was unavailable due to legal reasons, consistent with the reported “taken offline” status. DNS resolution points to IP 64.29.17.67, which belongs to Amazon.com, Inc. (AS16509) in the United States, a common hosting provider for disposable phishing sites.
The site employed HSTS, a standard security header, but this does not mitigate the underlying impersonation. VirusTotal scans flagged the domain by 15 of 95 security vendors, and the domain appears on at least one external blocklist, confirming that multiple security engines consider it malicious. PhishDestroy has also listed the site as blocked. The registrar information shows the domain was registered through Vercel Inc., a platform that allows rapid deployment of short‑lived domains.
No nameserver data were returned, and the domain is currently offline, limiting immediate observation of payloads. Defenders should continue to block the domain at network and email gateways, ensure that any URL filtering solutions reference the observed blocklist entries, and monitor for additional domains that use the same Vercel‑based deployment pattern targeting Trezor users. Threat intelligence feeds should be updated with the observed indicators—domain name, IP address, SSL certificate fingerprint, and HTTP 451 response—to support rapid detection of re‑hosted copies.
Informazioni sulla sicurezza di rete
Pipeline di risposta alle minacce
Stato della lista di blocco pubblica
Tecnologie · 2 identified
Vercel is a cloud platform for static frontends and serverless functions.
vercel.com Confidenza al 100%HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org Confidenza al 100%Analisi di VirusTotal
Prove archiviate
Dati e relazioni esterne
Questo sito ti ha influenzato in qualche modo?
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.
Verifica qualsiasi dominio
Analisi delle minacce utilizzando blocklist archiviate, WHOIS, DNS e prove di scansione pubblica
Scansiona oraSegnala un tentativo di phishing
Segnala i domini sospetti al nostro database delle minacce — proteggi la comunità
SegnalaFeed in tempo reale sulle minacce
Segnalazioni recenti di phishing e modifiche osservate della disponibilità
MonitoraRimani informato, rimani al sicuro
Controlla le minacce in tempo reale oppure contesta questa segnalazione se ritieni che si tratti di un falso positivo