trezor-data[.]gxtigroup[.]com
“Index of /”
Kanıt özeti
The domain trezor-data.gxtigroup.com was observed being used in a brand‑impersonation campaign targeting the cryptocurrency hardware wallet provider Trezor. VirusTotal records show that 11 of 93 scanned security vendors flagged the domain as malicious, indicating a moderate level of detection across the ecosystem. The site was registered on 21 February 2026 and, at the time of analysis (23 July 2026), the host has taken the service offline. PhishDestroy listed the domain on its blocklist, and the domain also appears on a single external security blocklist, reinforcing the view that it was actively being used for malicious purposes.
The SSL certificate presented is identified as “R12”, a detail that aligns with typical short‑lived certificates used by transient phishing infrastructure. Gridinsoft assigned a trust score of 0 out of 100, the lowest possible rating, further confirming the domain’s lack of legitimacy. The HTTP response returned the generic page title “Index of /”, which provides no functional content but is consistent with a placeholder page often employed to hide malicious payloads. The campaign has been classified as a crypto‑scam, and the domain explicitly impersonates the Trezor brand, suggesting that victims may have been directed to submit wallet credentials or seed phrases.
Because the hosting IP, registrar, and ASN information were not disclosed in the available intelligence, the full infrastructure footprint remains partially unknown. Defenders should ensure that the domain is added to DNS and URL filtering blocklists, monitor for any residual traffic to the associated IP ranges, and update incident response playbooks to include Trezor‑related impersonation indicators. Continuous re‑evaluation is advised in case the domain is re‑hosted or the underlying infrastructure is reused in future campaigns.
Data Coverage
Tehdit Müdahale Pipeline
Engelleme listesi kapsamı
10 izlenen harici kaynak · kayıtlı anlık görüntü 12.08.2026
Adli İstihbarat
VirusTotal Analizi
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin