セキュリティレポートへ移動
⚠️
このドメインは悪意のあるものとして報告されています
検出を報告するセキュリティ エンジン: 15。 細心の注意を払ってください — 資格情報や個人情報を入力しないでください。
ドメインのセキュリティと脅威インテリジェンス

trezor-exclusive-9dc8d4[.]webflow[.]io

“Trezor Exclusive – Balkan Kultur, Musik & Events in Niederurnen”

脅威の評決 クリティカル 100/100 証拠スコア
可用性 未検証 現在の到達可能性は未検証です
VirusTotal 検出数: 15/91 ブランドの偽装: Trezor
2026年7月23日 Trezor CDN
レポート概要

trezor-exclusive-9dc8d4.webflow.io — 未検証. ブランドの偽装: Trezor; 詐欺タイプ: Crypto Drainer. 証拠の概要: VirusTotal 15/91 (alphaMountain.ai, BitDefender, ESET, Emsisoft, Forcepoint ThreatSeeker); URLScan malicious verdict; CF Radar malicious; PhishDestroy score 100/100. レジストラ: Webflow.

元のフォレンジック記録を保持するため、下の PhishDestroy AI 詳細分析は英語のままです。

証拠の概要
重要
Ref
96681002
スコア
100/100

trezor-exclusive-9dc8d4.webflow.io is an active crypto‑drainer site hosted on Webflow’s infrastructure. The domain resolves to the IPv4 address 172.64.151.8, which belongs to Webflow’s content‑delivery network. Registration data indicates the domain was created through Webflow, Inc., and the nameserver lookup returned no records, consistent with Webflow’s default DNS handling. VirusTotal has recorded 11 detections out of 91 scanned security vendors, confirming that a subset of scanners classify the domain as malicious. The domain is currently listed on one external blocklist and has been explicitly blocked by the PhishDestroy service, reinforcing the malicious classification.

The threat intelligence rating assigns a high risk level, and the campaign remains active as of the report date, July 23 2026. Publicly available information does not include a page title, SSL certificate details, HTTP response codes, or any observed payload. Consequently, the exact technique used to drain cryptocurrency wallets cannot be confirmed, and the presence of a specific phishing kit or additional command‑and‑control infrastructure remains uncertain. Defenders should treat the domain as hostile and incorporate it into perimeter defenses.

Immediate actions include adding the fully qualified domain name and its resolved IP address to DNS‑based blocklists, updating web‑proxy and firewall rules to deny outbound connections to 172.64.151.8, and ensuring that endpoint detection platforms ingest the VirusTotal detection count. Continuous monitoring of Webflow‑hosted assets for newly created subdomains with similar naming patterns is advised, as the platform’s ease of provisioning can be abused for rapid campaign iteration. Correlating internal logs for any traffic to this domain with user authentication attempts may reveal compromised credentials. Organizations should also share any observed indicators of compromise with relevant threat‑sharing communities to improve collective detection.

VirusTotal
VirusTotal
15 det.
CFレーダー
悪意あり
ScamAdviser
Scamadviser
15/100
TLS証明書
Google Trust Services
観測ステータス
未検証
PhishDestroy
DestroyList
掲載あり
データの網羅性 VirusTotal 15 / 91 URLQuery チェックされていない PhishStats チェックされていない OTX no community references CFレーダー provider verdict: malicious URLScan capture 保存されたレポート URLScan verdict malicious DNSブロック チェックされていない TLS valid certificate, 32d WHOIS not parsed スクリーンショット 2 captures · 2 sources リダイレクトチェーン 調査されていない Scamadviser 15/100
ネットワークセキュリティインテリジェンス
CF Cloudflare Radar Verdict 悪意あり
Phishing

脅威対応 Pipeline

ディスカバリー
Checks
Reports
可用性
12/14

公開ブロックリスト登録状況

保存済みキャプチャ

ドメイン・インテリジェンス

ドメイン
URLScan Verdict 悪意あり score 100 Phishing brand: Trezor report ↗
サーバー / ASN cloudflare · AS13335 Cloudflare, Inc.
IP Context Cloudflare shared edge origin IP hidden Edge-IP の評判はこのドメインに起因しません。
Registrar (base domain) Webflow MY(MY)
不正利用連絡先abuse@webflow.com
ICANNレジストリICANN公認レジストラ →
IPアドレス 172.64.151.8 CDN
地域CA Toronto, CA
ネットワークAS13335 · Cloudflare, Inc.
発信元 IP は CDN プロキシの背後に隠されています。エッジ アドレスのリバース IP の結果には、無関係なテナントが含まれています。発信元を見つけるには、パッシブ DNS または証明書の透明性データが必要です。
技術的な詳細DNS、SSL SAN、タイムスタンプ
初確認2026年7月23日
DOM Analysisanalyzed 2026年7月23日score 93/100
IoC Extractionscanned 2026年7月29日0 wallet · 0 Telegram IoCs
Submitted URLhttp://trezor-exclusive-9dc8d4.webflow.io/
TLS Fingerprint
TLS Observationvalid from 2026年5月27日scanned 2026年7月23日
TLS SAN Domainswebflow.io
Favicon Hash
ページタイトル
Trezor Exclusive – Balkan Kultur, Musik & Events in Niederurnen
TLS証明書
Valid transport encryption · 発行者 Google Trust Services · valid for 32 days
脅威情報の照合 · source references
ScamAdviser Public lookup
A public ScamAdviser lookup is available. Review its current score and warnings at the source; the existence of a lookup page is not itself a malicious verdict.
View on ScamAdviser
Live-fetched via CF worker proxy pool · cached 24h
使用技術 · 5 identified
jQuery
JavaScript libraries

jQuery is a JavaScript library which is a free, open-source software designed to simplify HTML DOM tree traversal and manipulation, as well as event handling, CSS animation, and Ajax.

jquery.com 信頼度 100%
Google Hosted Libraries
CDN

Google Hosted Libraries is a stable, reliable, high-speed, globally available content distribution network for the most popular, open-source JavaScript libraries.

developers.google.com 信頼度 100%
Google Font API
Font scripts

Google Font API is a web service that supports open-source font files that can be used on your web designs.

google.com 信頼度 100%
Cloudflare
CDN

Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.

www.cloudflare.com 信頼度 100%
HTTP/3
Miscellaneous

HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.

httpwg.org 信頼度 100%
Detected via Cloudflare Radar · Wappalyzer engine
このドメインを報告する 証拠を提出し、他の人を守る手助けをしましょう

VirusTotalによる分析

15 / 91 セキュリティ ベンダーがこのドメインにフラグを立てました
View on VT
Last analyzed Previous stored snapshot: 11 detections
alphaMountain.ai
BitDefender
ESET
Emsisoft
Forcepoint ThreatSeeker
Fortinet
G-Data
Gridinsoft
カスペルスキー
Lionic
MalwareURL
ネットクラフト
ソフォス
VIPRE
Webroot

アーカイブ済み証拠

Wayback Machine Snapshot
過去のスナップショットは証拠のレビューに利用可能です
View Archive
サイトパフォーマンス分析

Google PageSpeed Insights — mobile performance audit of trezor-exclusive-9dc8d4.webflow.io · checked Jul 23, 2026

74
Needs Work
Performance
FCP
3.19s
First Contentful Paint
LCP
5.44s
Largest Contentful Paint
CLS
0.037
Cumulative Layout Shift
TBT
0ms
Total Blocking Time
SI
3.19s
Speed Index
Powered by Google PageSpeed Insights · Mobile strategy · Scores: 90-100 Good 50-89 Needs Work 0-49 Poor

証拠および外部報告書

このサイトによって何か影響を受けましたか?

If credentials were compromised, report immediately. Do not engage with recovery scammers.

アカウント資格情報、個人情報、支払い情報を入力した場合、またはこのドメインからファイルをダウンロードした場合は、すぐに対処してください。インシデントを報告し、自分自身を守るのに役立つリソースを以下に示します。

ユーロポール
EU 加盟国の公式報告チャネルを見つける
National police directory
復旧を装った詐欺に注意! 犯罪者は、捜査員、弁護士、または回収業者を装い、被害者に再び連絡を取る可能性があります。 前払い料金を支払ったり、資格情報を共有したりしないでください。 回復詐欺について詳しくはこちら →

お住まいの地域の当局へ報告してください

サイバー犯罪の公式連絡先 または 苦情草稿を作成する → を取得するには、国を選択してください。

97か国のディレクトリ
AI 支援ドラフト — インシデントの詳細は AI プロバイダーによって処理されます 自分で確認して送信する

任意のドメインを確認する

保存されたブロックリスト、WHOIS、DNS、および公開スキャン証拠を使用した脅威分析

今すぐスキャン

フィッシングを報告する

不審なドメインを当社の脅威データベースに報告してください — コミュニティを守りましょう

レポート

リアルタイム脅威情報フィード

最近のフィッシングレポートと観察された可用性の変化

監視

最新情報を入手し、安全を確保しましょう

リアルタイムの脅威を監視するか、誤検知だと思われる場合はこのリストに異議を申し立ててください

リアルタイム脅威情報フィード この掲載情報について異議を申し立てる
HTML · IFRAME

このレポートを埋め込む

この脅威情報を、ご自身のウェブサイトやブログで共有してください

embed.html
<iframe
  src="https://phishdestroy.io/ja/embed/domain/trezor-exclusive-9dc8d4.webflow.io"
  title="PhishDestroy threat report for trezor-exclusive-9dc8d4.webflow.io"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>