Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is network-abuse@google.com.
The latest stored availability evidence still shows the domain reachable; 1 month has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
trezor-iostarts[.]blogspot[.]com[.]ee
“Trezor.io/Start® — Secure Wallet Setup & Get Started with Your Trezor Device”
trezor-iostarts.blogspot.com.ee — Não verificado. Representação da marca: Trezor; Tipo de golpe: Brand Impersonation. Resumo das evidências: VirusTotal 17/91 (ADMINUSLabs, ChainPatrol, alphaMountain.ai, BitDefender, Chong Lua Dao); URLQuery 3 alerts; URLScan malicious verdict; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 95/100. Registrador: Google Blogger.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
The domain trezor-iostarts.blogspot.com.ee is currently active and associated with a cryptocurrency drainage operation (crypto drainer). Analysis indicates this infrastructure is deployed to facilitate unauthorized fund transfers from cryptocurrency wallets. The threat remains under active investigation as of the latest assessment cycle.
Infrastructure analysis reveals the domain resolves to IP 142.251.20.132 and is hosted on Blogger infrastructure. As of the most recent scan, 11 of 95 VirusTotal vendors flagged this domain, indicating a lack of immediate detection by antivirus engines. No blocklist entries were identified during the current assessment. Creation date and registrar information remain unconfirmed due to the use of a free hosting service, which obscures registration metadata. Trust scores and additional reputation metrics are not available from standard registrars.
Current status indicates the domain remains active and actively serving malicious content. Organizations and users should implement network-level blocking for this domain and its associated infrastructure. Recommendations include monitoring for outbound connections to this domain or IP and inspecting DNS resolution anomalies. Users interacting with cryptocurrency platforms are advised to verify website authenticity through independent channels before engaging in transactions.
Inteligência de segurança de rede
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Análise do VirusTotal
Evidências e relatórios externos
PD-20260624-EE3005 Recipient: network-abuse@google.com Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo