trezor-website-ram-pod-paint-sigma-gole-324324-psi[.]vercel[.]app
“Connect & Find Your Trezor”
trezor-website-ram-pod-paint-sigma-gole-324324-psi.vercel.app — 콘텐츠를 사용할 수 없음. 브랜드 사칭: Trezor; 사기 유형: Crypto Scam. 증거 요약: VirusTotal 9/95 (ADMINUSLabs, alphaMountain.ai, BitDefender, CyRadar, Fortinet); URLScan malicious verdict; PhishDestroy score 77/100. 등록기관: Vercel.
원본 포렌식 기록을 보존하기 위해 아래의 상세 PhishDestroy AI 분석은 영어로 유지됩니다.
The domain trezor-website-ram-pod-paint-sigma-gole-324324-psi.vercel.app was registered through Vercel Inc. and resolves to the Amazon‑owned IP address 216.198.79.3, associated with ASN 16509. The site served a page titled “Connect & Find Your Trezor” and presented a TLS certificate issued by Google Trust Services under the WR1 root, indicating a valid HTTPS connection. Infrastructure analysis shows the use of Vercel hosting and the presence of HTTP Strict Transport Security (HSTS). The domain returned HTTP status 451, indicating that the content was unavailable for legal reasons, and it is currently listed as taken offline.
The site impersonates the Trezor hardware‑wallet brand and is classified as a crypto‑scam. It was blocked by the PhishDestroy blocklist and appears on a single security blocklist. VirusTotal scans recorded nine detections out of ninety‑five engines, reinforcing the malicious classification. Nameserver information is unavailable (NS_NOT_FOUND).
The evidence confirms that the domain was created to lure Trezor users into a credential‑harvesting flow, leveraging a legitimate‑looking page title and a trusted SSL certificate to increase credibility. Uncertainty remains regarding the specific payload delivered to victims, as the page content has not been captured and no visual artefacts have been disclosed. Defenders should continue to monitor the IP range owned by Amazon for similar Vercel‑hosted impersonation attempts, enforce blocklist updates to include this domain, and advise users to verify URLs against official Trezor resources. Threat intelligence feeds should flag the domain as a brand‑impersonation crypto scam, and any residual DNS entries should be purged to prevent resurrection attempts.
위협 대응 Pipeline
공개 차단 목록 상태
사용 기술 · 2 identified
Cloud platform for frontend deployment, optimized for Next.js.
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
VirusTotal 분석
보관된 증거
증거 및 외부 보고서
이 사이트로 인해 영향을 받으셨나요?
계정 자격 증명, 개인 정보 또는 결제 정보를 입력했거나 이 도메인에서 파일을 다운로드한 경우 즉시 조치를 취하세요. 다음은 사건을 신고하고 자신을 보호하는 데 도움이 되는 리소스입니다.
지역 당국에 신고하십시오
공식 사이버 범죄 연락처 또는 불만사항 초안 작성 →를 받으려면 국가를 선택하세요.