trazor-suites[.]created[.]app
“Trezor Suite”
trazor-suites.created.app — Контент недоступен. Олицетворение бренда: Trezor; Тип мошенничества: Crypto Scam. Сводка доказательств: VirusTotal 6/95 (CyRadar, ESET, Kaspersky, SOCRadar, URLQuery); URLScan malicious verdict; Spamhaus DBL_PHISH; PhishDestroy score 68/100. Регистратор: Tucows.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
The domain trazor-suites.created.app is a confirmed phishing site engaged in brand impersonation targeting Trezor, a cryptocurrency hardware wallet provider. It presents itself as the legitimate Trezor Suite interface to deceive users into entering sensitive credentials or wallet information, posing an elevated risk of cryptocurrency theft. No drainer kit was detected, but the site was operational long enough to collect victim data before being taken offline.
Technical analysis shows trazor-suites.created.app was flagged by 6 of 95 security vendors on VirusTotal, including CyRadar, ESET, and Kaspersky. It was registered through Tucows Domains Inc. on July 12, 2023, and resolved to IP address 52.222.214.100, hosted on Amazon.com, Inc. infrastructure in Germany. The domain appeared on one security blocklist (PhishDestroy) and used a Let's Encrypt SSL certificate. Observed technologies included Vercel and HSTS, with nameservers ns1.vercel-dns.com and ns2.vercel-dns.com. The page title mimicked the legitimate 'Trezor Suite' and returned a 404 HTTP status when accessed.
Users who interacted with trazor-suites.created.app should immediately revoke any token approvals and transfer cryptocurrency to a new, secure wallet. Change all passwords associated with the impersonated brand and enable two-factor authentication (2FA) on all accounts. Monitor financial and transaction history for unauthorized activity. Report the phishing domain to the impersonated brand (Trezor), the hosting provider (Vercel), and relevant authorities such as the Anti-Phishing Working Group (APWG) or local cybercrime units.
Процесс реагирования на угрозы
Статус в публичных блок-листах
Сохранённый снимок
Аналитика доменов
Технические сведенияDNS, SAN в протоколе SSL, временные метки
ICANN OVERSIGHT
Registration: created.app
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For the registrable domain created.app behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Технологии · 2 identified
Vercel is a cloud platform for static frontends and serverless functions.
vercel.com 100% уверенностиHTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 100% уверенностиАнализ VirusTotal
Архивные доказательства
Доказательства и внешние отчеты
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание