trezer-io-faq[.]pages[.]dev
“Trezor.io/start | Secure Wallet Setup”
Kaydedilmiş gözlem
Gözlemlenen başlık farkı
Kanıt özeti
The domain trezer-io-faq.pages.dev was registered on March 23, 2026 through Cloudflare, Inc., and resolves to the Cloudflare‑hosted address 172.66.44.135, which is geo‑located to Canada. The site presents the page title "Trezor.io/start | Secure Wallet Setup", indicating a direct attempt to mimic the official Trezor onboarding flow. Analysis of the TLS certificate shows it is issued by Google Trust Services under the WE1 intermediate, confirming the use of a legitimate certificate chain but not providing any assurance about the content hosted behind it. The domain employs HSTS, Cloudflare’s edge services, and HTTP/3, all typical of legitimate sites but also useful for attackers seeking reliable delivery.
Security‑vendor scans on VirusTotal flagged the domain in 14 of 94 engines, and it appears on one external blocklist, prompting PhishDestroy to block it. Gridinsoft assigns a trust score of 0 / 100, reflecting extreme suspicion. The HTTP response returned a 403 status code, and the domain is currently taken offline, which limits immediate threat exposure but does not eliminate the risk of re‑activation or reuse of the same infrastructure. The site is classified as a crypto scam targeting Trezor users, and it impersonates the Trezor brand as explicitly indicated in the intelligence.
Uncertainties remain regarding the exact payload delivered when the site was active, as no page content has been captured. Defenders should continue to block the domain at perimeter and DNS layers, monitor Cloudflare‑registered domains that incorporate the "trezer" string or similar typo‑squatting patterns, and watch for re‑registration of the IP address or related subdomains. Adding the domain to internal blocklists and sharing the indicator set with threat‑sharing communities will help curb potential re‑use.
Data Coverage
Ağ Güvenliği İstihbaratı
Tehdit Müdahale Pipeline
Engelleme listesi kapsamı
10 izlenen harici kaynak · kayıtlı anlık görüntü 11.08.2026
Topluluk raporları
1 topluluk üyesi tarafından bildirildi; ilk görülme 22.03.2026
- Kayıtlı raporlar
- 1
- Bildirilen benzersiz URL’ler
- 1
Topluluk istihbaratı
1 topluluk raporu
KategoriPHISHING
The PhishFort Detection System has flagged this as a domain threat, classified as phishing. Associated tags: subdomain, typosquat. Threat detected at 2026-04-15T16:35:23.213Z.
VirusTotal Analizi
Site Performans Analizi
Google PageSpeed Insights — mobile performance audit of trezer-io-faq.pages.dev · checked Mar 23, 2026
Benzer alan adları
74 kayıtlı benzer alan adı
Tümünü göster (62)
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin