app[.]trezoriosstart[.]com
“Trezor.io/Start | Trezor Hardware Wallet (Official)”
Resumo das evidências
This domain, app.trezoriosstart.com, poses a direct threat to users of Trezor hardware wallets by impersonating the official Trezor.io/Start setup page. The site is designed to deceive visitors into entering sensitive recovery seed phrases or private keys under the false pretense of wallet initialization. Such credentials, once captured, grant attackers full access to cryptocurrency holdings, enabling immediate and irreversible theft. The page title, 'Trezor.io/Start | Trezor Hardware Wallet (Official)', is crafted to mimic legitimacy, exploiting user trust in the Trezor brand during critical setup processes. Analysis indicates this domain was registered on May 22, 2025, through Dynadot LLC, a registrar frequently abused for malicious infrastructure. It resolves to IP address 188.114.97.3, hosted on Cloudflare’s network (AS13335), which provides anonymity and resilience to takedown efforts. The SSL certificate, issued by Google Trust Services (WE1), further lends a false sense of security. Security vendors on VirusTotal flagged this domain as malicious, with 19 out of 95 engines detecting it as a phishing site. Additionally, the domain appears on one security blocklist, confirming its classification as a confirmed threat rather than a false positive. Users who visited app.trezoriosstart.com should assume their recovery seed or private key has been compromised. Immediately cease all interactions with the site and disconnect any hardware wallets connected during the visit. Transfer all cryptocurrency assets to a new, secure wallet using a trusted device and a verified official Trezor setup page. Monitor all linked accounts for unauthorized transactions and enable multi-factor authentication where available. Report the incident to relevant security teams and consider filing a report with local cybercrime authorities to aid in tracking the threat actors behind this infrastructure.
Data Coverage
Sinais de segurança
Inteligência de segurança de rede
Pipeline de resposta a ameaças
Cobertura de listas de bloqueio
10 fontes externas monitoradas · instantâneo de 13/08/2026
Linha do tempo de detecção
-
VirusTotal
19 → 17
-
VirusTotal
17 → 16
-
VirusTotal
16 → 17
Captura armazenada
Inteligência de Domínios
Detalhes técnicosDNS, nomes TLS e datas
ICANN OVERSIGHT
Registration: trezoriosstart.com
Credenciamento e contexto RAA
Credenciamento e contexto RAA
Registrar accreditation and DNS abuse obligations
For the registrable domain trezoriosstart.com behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Análise do VirusTotal
Análise de desempenho do site
Google PageSpeed Insights — mobile performance audit of app.trezoriosstart.com · checked Mar 1, 2026
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo