help-trezorhdwlare[.]gitbook[.]io
Сводка доказательств
The domain help-trezorhdwlare.gitbook.io has been confirmed as a brand impersonation resource specifically targeting Trezor cryptocurrency wallet users. Analysis indicates this infrastructure was designed to mimic legitimate Trezor support documentation and interfaces, presenting an elevated risk of credential harvesting or cryptocurrency theft. The domain is currently offline, though prior activity suggests it may reappear under modified infrastructure. Infrastructure analysis reveals the domain resolved to IP address 104.18.40.47, geolocated to Cloudflare, Inc. in Canada. The resource was flagged by 16 of 95 security vendors on VirusTotal, with detection labels including phishing and brand impersonation. Registration occurred through GitBook, a platform commonly exploited for hosting malicious documentation due to its perceived legitimacy. The domain appears on one security blocklist, and its SSL certificate was issued by Google Trust Services (WE1). Creation date records indicate the domain was established on April 26, 2026, though this timestamp may reflect platform-specific registration rather than traditional WHOIS data. Current status indicates the domain has been taken offline, though the underlying threat remains active. Organizations and individuals are advised to monitor for reemergence under similar naming conventions or alternative hosting platforms. Users who accessed this domain should immediately rotate credentials for any associated cryptocurrency wallets or services. Security teams should update detection rules to include the observed IP address and certificate authority details. Given the targeted nature of this campaign, heightened vigilance is recommended for Trezor-related communications, particularly those hosted on third-party documentation platforms.
Data Coverage
Данные сетевой безопасности
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DigiCert UltraDNS | help-trezorhdwlare.gitbook.io |
malicious | Sinkholed |
Процесс реагирования на угрозы
Проверка по блок-листам
10 внешних источников под наблюдением · снимок от 11.08.2026
10 внешних источников под наблюдением Совпадений нет
Хронология обнаружения
-
Cloudflare Radar
Сканирование Cloudflare Radar сохранено · Открыть сканирование
Аналитика доменов
Технические деталиDNS, имена TLS и временные метки
Технологии
Выявлено 2 технологии с высокой уверенностью
Анализ VirusTotal
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание