docs-trezr-en[.]square[.]site
“404 - Page Not Found”
docs-trezr-en.square.site — Контент недоступний. Уособлення бренду: Trezor; Тип шахрайства: Wallet/seed Phishing. Зведення доказів: VirusTotal 11/95 (alphaMountain.ai, BitDefender, CyRadar, Forcepoint ThreatSeeker, Fortinet); CF Radar malicious; PhishDestroy score 88/100. Реєстратор: MarkMonitor.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
This domain, docs-trezr-en.square.site, poses as an official Trezor hardware wallet interface to deceive users into entering sensitive credentials, such as recovery seeds or private keys. Brand impersonation attacks of this nature are designed to harvest cryptocurrency wallet access details, leading to unauthorized asset transfers and irreversible financial loss. The site mimics legitimate wallet management portals, often leveraging urgency or fake security alerts to manipulate victims into disclosing confidential information. Analysis indicates the domain was registered on February 5, 2019, through MarkMonitor, Inc., a registrar commonly associated with both legitimate and malicious domains. Security vendors flagged this domain as malicious, with 11 out of 95 engines on VirusTotal detecting it as a threat. Infrastructure analysis reveals the domain resolves to 74.115.51.4, hosted on AS27647 (Weebly, Inc.), a platform frequently exploited for phishing due to its ease of domain creation and hosting. The domain appears on two security blocklists and uses a Let's Encrypt SSL certificate, which, while providing encryption, does not validate legitimacy. If a user visited this domain or interacted with its content, immediate action is required. First, disconnect the device from the internet to prevent potential data exfiltration. Next, assume any entered credentials or recovery phrases are compromised and initiate recovery procedures for the affected wallet. Generate a new wallet address and transfer remaining assets to it using a verified, secure device. Monitor all linked accounts for unauthorized transactions and enable multi-factor authentication where available. Report the incident to relevant security teams and consider notifying the impersonated brand to aid in takedown efforts.
Сигнали безпеки
Розвіддані з мережевої безпеки
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Збережений знімок
Аналітика доменів
Технічні деталіDNS, SAN-адреси SSL, мітки часу
ICANN OVERSIGHT
Registration: square.site
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For the registrable domain square.site behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Технології · 2 identified
Cloud computing platform offering compute, storage, and networking services.
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comАналіз VirusTotal
Архівні докази
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога