app[.]trezoriosstart[.]com
“Trezor.io/Start | Trezor Hardware Wallet (Official)”
This domain, app.trezoriosstart.com, poses a direct threat to users of Trezor hardware wallets by impersonating the official Trezor.io/Start setup page. The site is designed to deceive visitors into entering sensitive recovery seed phrases or private keys under the false pretense of wallet initialization. Such credentials, once captured, grant attackers full access to cryptocurrency holdings, enabling immediate and irreversible theft. The page title, 'Trezor.io/Start | Trezor Hardware Wallet (Official)', is crafted to mimic legitimacy, exploiting user trust in the Trezor brand during critical setup processes. Analysis indicates this domain was registered on May 22, 2025, through Dynadot LLC, a registrar frequently abused for malicious infrastructure. It resolves to IP address 188.114.97.3, hosted on Cloudflare’s network (AS13335), which provides anonymity and resilience to takedown efforts. The SSL certificate, issued by Google Trust Services (WE1), further lends a false sense of security. Security vendors on VirusTotal flagged this domain as malicious, with 19 out of 95 engines detecting it as a phishing site. Additionally, the domain appears on one security blocklist, confirming its classification as a confirmed threat rather than a false positive. Users who visited app.trezoriosstart.com should assume their recovery seed or private key has been compromised. Immediately cease all interactions with the site and disconnect any hardware wallets connected during the visit. Transfer all cryptocurrency assets to a new, secure wallet using a trusted device and a verified official Trezor setup page. Monitor all linked accounts for unauthorized transactions and enable multi-factor authentication where available. Report the incident to relevant security teams and consider filing a report with local cybercrime authorities to aid in tracking the threat actors behind this infrastructure.
Сигнали безпеки
Розвіддані з мережевої безпеки
Процес реагування на загрози Pipeline
Перевірка за блок-листами
Джерел: 10 · синхронізовано 10.08.2026
Хронологія виявлення
Збережені спостереження у хронологічному порядку.
-
VirusTotal
VirusTotal: 19 → 17
-
VirusTotal
VirusTotal: 17 → 16
-
VirusTotal
VirusTotal: 16 → 17
Повідомлення спільноти
Повідомили учасники спільноти: 1; уперше помічено 26.11.2025
- Збережені повідомлення
- 1
- Унікальні URL
- 1
Дані спільноти
Звітів спільноти: 1
КатегоріяPHISHING
The PhishFort Detection System has flagged this as a domain threat, classified as phishing. Associated tags: brand impersonation. Threat detected at 2024-06-20T03:21:55.237Z.
Збережений знімок
Аналітика доменів
Технічні подробиціDNS, імена TLS і часові мітки
ICANN OVERSIGHT
Registration: trezoriosstart.com
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For the registrable domain trezoriosstart.com behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Аналіз VirusTotal
Аналіз продуктивності сайту
Google PageSpeed Insights — mobile performance audit of app.trezoriosstart.com · checked Mar 1, 2026
Схожі домени
Збережено схожих доменів: 74
Показати всі (62)
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога