trezor-help.support
“Trezor Wallet Recovery”
trezor-help.support is an active brand impersonation scam targeting Trezor users. Flagged by 22/95 VirusTotal vendors as a crypto drainer threat, this domain.
L’analisi dettagliata di PhishDestroy AI resta in inglese per preservare il rapporto forense originale.
Riepilogo delle prove
The domain trezor-help.support is currently active and operates as a brand impersonation scam specifically targeting Trezor, a well-known cryptocurrency hardware wallet provider. Analysis confirms this domain is designed to deceive users into entering sensitive wallet recovery information, likely functioning as a crypto drainer to siphon digital assets from victims. The site remains operational despite multiple security detections, posing a high-risk threat to unsuspecting users seeking wallet recovery services. Infrastructure analysis reveals the domain was registered on June 15, 2026, through Name.com, Inc., an uncommon future registration date that may indicate an attempt to evade immediate detection. The domain resolves to IP address 34.111.179.208 and uses an SSL certificate issued by Let's Encrypt (identifier E7), providing a false sense of security. Security vendors have flagged this domain in 22 of 95 VirusTotal scans, with active blocks implemented by PhishDestroy, MetaMask, and SEAL. The domain appears on three distinct security blocklists, and its page title, 'Trezor Wallet Recovery,' directly mimics official Trezor support pages to enhance credibility. Current threat status remains active, with no indications of takedown or mitigation. Users are strongly advised to avoid interacting with this domain and any associated pages. Trezor wallet holders should exclusively use the official support channels verified through the legitimate Trezor website. Security teams are recommended to update blocklists with the domain and IP address, monitor for similar impersonation attempts, and educate users on verifying domain authenticity before entering sensitive wallet information. The combination of brand impersonation, active security flags, and direct targeting of cryptocurrency recovery processes underscores the critical need for heightened vigilance in this threat landscape.
Informazioni sulla sicurezza di rete
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Cloudflare DNS | trezor-help.support |
malicious | Sinkholed |
| OpenDNS | trezor-help.support |
phishing | Phishing Block |
| DigiCert UltraDNS | trezor-help.support |
malicious | Sinkholed |
| Hagezi Threat Feed | trezor-help.support |
malicious | Sinkholed |
| DNS4EU | trezor-help.support |
malicious | Sinkholed |
| Quad9 DNS | trezor-help.support |
malicious | Sinkholed |
Forensic History & Detection Timeline
-
Cloudflare Radar Scan Jun 26, 2026 · 05:35 UTCCloudflare Radar scan registered: View Radar report.
Pipeline di risposta alle minacce
Stato della lista di blocco pubblica
Evasion analysis
Cloaking suspected: scanner and victim titles differ
Stored crawler-versus-browser observations for this host, plus a live fingerprint check for Keitaro-style traffic distribution systems.
- Stored cloaking flag
- Not observed
- Punteggio di cloaking
- 0/6
- Last cloaking scan
Scanner note: dead_http: raw=http_404; http=404; via=https_proxy
Acquisizione salvata · 3 sources
Analisi dei domini
Dettagli tecniciDNS, SAN SSL, timestamp
ICANN OVERSIGHT
Accreditamento e contesto RAA
Accreditamento e contesto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Tecnologie · 7 identified
Analisi di VirusTotal
Domini simili
74 domini simili memorizzati
Mostra tutto (62)
Intelligence della comunità
1 segnalazione della comunità
CategoriaIMPERSONATION
The domain is a live, recently registered site that presents itself as Trezor and uses wallet-recovery language aimed at crypto users. The page includes calls to recover a wallet using a recovery phrase, which is consistent with seed-phrase harvesting and phishing behavior rather
Segnalazioni della comunità
Segnalato da 1 membro della comunità; prima osservazione il 15/06/2026
- Segnalazioni memorizzate
- 1
- URL segnalati univoci
- 1
Dati e relazioni esterne
“The domain is a live, recently registered site that presents itself as Trezor and uses wallet-recovery language aimed at crypto users. The page includes calls to recover a wallet using a recovery phrase, which is consistent with seed-phrase harvesting and phishing behavior rather than legitimate support content. The domain is independently registered and hosted, so removal of the hosted content plus registrar suspension is warranted; internal blocklisting is also appropriate to reduce exposure w”
PD-20260617-C4F1EA Recipient: abuse@name.com Abuse notice text as sent to the provider
Policy Violations: Illegal Activities: Active phishing operation targeting victims Fraud & Deception: Impersonation of legitimate services Identity Theft: Collection of credentials under false pretenses Applicable Laws (Unknown): International Anti-Cybercrime Regulations Budapest Convention on Cybercrime Universal Fraud Prevention Laws Phishing activities violate international cybercrime conventions and Unknown's domestic fraud laws. Action Required: This evidence-backed report demonstrates clear violations requiring suspension per your policies. Continued hosting exposes your organization to regulatory scrutiny and potential legal liability.
Questo sito ti ha influenzato in qualche modo?
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.
Verifica qualsiasi dominio
Analisi delle minacce utilizzando blocklist archiviate, WHOIS, DNS e prove di scansione pubblica
Scansiona oraSegnala un tentativo di phishing
Segnala i domini sospetti al nostro database delle minacce — proteggi la comunità
SegnalaFeed in tempo reale sulle minacce
Segnalazioni recenti di phishing e modifiche osservate della disponibilità
MonitoraRimani informato, rimani al sicuro
Controlla le minacce in tempo reale oppure contesta questa segnalazione se ritieni che si tratti di un falso positivo