Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is abuse@omegatech.sc.
The latest stored availability evidence still shows the domain reachable; 4 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
trezor-suite[.]com[.]co
“Welcome”
trezor-suite.com.co — Непроверенный. Олицетворение бренда: Trezor; Тип мошенничества: Crypto Scam. Сводка доказательств: VirusTotal 18/91 (ADMINUSLabs, ChainPatrol, alphaMountain.ai, BitDefender, Certego); URLQuery 1 alert; Spamhaus DBL_PHISH; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 95/100. Регистратор: Hosting Concepts.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
The domain trezor-suite.com.co was registered on March 18 2026 through Hosting Concepts B.V. d/b/a Registrar.eu and is currently resolved to the IPv4 address 158.94.209.135. The host resides in the Netherlands and is associated with Omegatech LTD. Authoritative name servers are ns1.openprovider.nl, ns2.openprovider.be, and ns3.openprovider.eu. The web server reports Nginx and serves a single page whose title is "Welcome". The site redirects with HTTP status 301 and presents a Let’s Encrypt R12 certificate.
The content and branding are crafted to impersonate the hardware wallet provider Trezor, targeting cryptocurrency users. The page title "Welcome" and the domain name that incorporates the brand keyword are typical of brand‑impersonation campaigns. The presence of a valid TLS certificate does not mitigate the risk; the certificate is issued by Let’s Encrypt, a free CA, and offers no assurance of legitimacy.
Infrastructure analysis shows a Gridinsoft trust score of 0 out of 100, indicating a high likelihood of malicious activity. VirusTotal scans have flagged the domain in 17 of 95 security engines, and the domain appears on three independent security blocklists. It is already blocked by PhishDestroy, MetaMask, and SEAL, confirming that multiple anti‑phishing services have identified it as a cryptocurrency‑related scam.
Defenders should treat any traffic to trezor-suite.com.co as hostile. Blocking the domain at network perimeter and DNS resolvers will prevent credential harvesting. Users should be warned that the site is a brand‑impersonation vector and instructed to verify URLs against official Trezor domains. Continuous monitoring of the associated IP address and name servers is advised, as the infrastructure may be reused for further campaigns.
Данные сетевой безопасности
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| OpenDNS | trezor-suite.com.co |
phishing | Phishing Block |
Процесс реагирования на угрозы
Статус в публичных блок-листах
Технологии · 1 identified
High-performance HTTP server and reverse proxy, known for stability and low resource usage.
Анализ VirusTotal
Анализ производительности сайта
Google PageSpeed Insights — mobile performance audit of trezor-suite.com.co · checked Mar 22, 2026
Доказательства и внешние отчеты
PD-20260322-127DA8 Recipient: abuse@omegatech.sc Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание