app[.]trezoriosstart[.]com
“Trezor.io/Start | Trezor Hardware Wallet (Official)”
Сводка доказательств
This domain, app.trezoriosstart.com, poses a direct threat to users of Trezor hardware wallets by impersonating the official Trezor.io/Start setup page. The site is designed to deceive visitors into entering sensitive recovery seed phrases or private keys under the false pretense of wallet initialization. Such credentials, once captured, grant attackers full access to cryptocurrency holdings, enabling immediate and irreversible theft. The page title, 'Trezor.io/Start | Trezor Hardware Wallet (Official)', is crafted to mimic legitimacy, exploiting user trust in the Trezor brand during critical setup processes. Analysis indicates this domain was registered on May 22, 2025, through Dynadot LLC, a registrar frequently abused for malicious infrastructure. It resolves to IP address 188.114.97.3, hosted on Cloudflare’s network (AS13335), which provides anonymity and resilience to takedown efforts. The SSL certificate, issued by Google Trust Services (WE1), further lends a false sense of security. Security vendors on VirusTotal flagged this domain as malicious, with 19 out of 95 engines detecting it as a phishing site. Additionally, the domain appears on one security blocklist, confirming its classification as a confirmed threat rather than a false positive. Users who visited app.trezoriosstart.com should assume their recovery seed or private key has been compromised. Immediately cease all interactions with the site and disconnect any hardware wallets connected during the visit. Transfer all cryptocurrency assets to a new, secure wallet using a trusted device and a verified official Trezor setup page. Monitor all linked accounts for unauthorized transactions and enable multi-factor authentication where available. Report the incident to relevant security teams and consider filing a report with local cybercrime authorities to aid in tracking the threat actors behind this infrastructure.
Data Coverage
Сигналы безопасности
Данные сетевой безопасности
Процесс реагирования на угрозы
Проверка по блок-листам
10 внешних источников под наблюдением · снимок от 10.08.2026
8 внешних источников под наблюдением Совпадений нет
Хронология обнаружения
-
VirusTotal
19 → 17
-
VirusTotal
17 → 16
-
VirusTotal
16 → 17
Сохранённый снимок
Аналитика доменов
Технические деталиDNS, имена TLS и временные метки
ICANN OVERSIGHT
Registration: trezoriosstart.com
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For the registrable domain trezoriosstart.com behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Анализ VirusTotal
Анализ производительности сайта
Google PageSpeed Insights — mobile performance audit of app.trezoriosstart.com · checked Mar 1, 2026
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание