help-doc-trezor-suite[.]gitbook[.]io
Зведення доказів
The domain help-doc-trezor-suite.gitbook.io is identified as a brand impersonation threat specifically targeting Trezor, a well-known cryptocurrency hardware wallet provider. Analysis confirms the domain is currently offline, though prior activity suggests malicious intent to mislead users into disclosing sensitive information or interacting with fraudulent interfaces. The infrastructure was designed to closely resemble official Trezor documentation or support resources, increasing the likelihood of successful deception among users seeking legitimate assistance. Infrastructure analysis reveals the domain was created on May 11, 2026, and registered through GitBook, a platform commonly used for documentation hosting. It resolved to the IP address 172.64.147.209, geolocated in Canada and associated with Cloudflare, Inc. The domain was flagged by 17 of 95 security vendors on VirusTotal, indicating moderate consensus regarding its malicious nature. Additionally, the SSL certificate was issued by Google Trust Services (WE1), a detail often exploited by threat actors to lend a false sense of legitimacy. The domain appeared on one security blocklist prior to being taken offline, further supporting its classification as a threat. Current status indicates the domain has been deactivated, reducing immediate risk to users. However, similar infrastructure may re-emerge under different domains or hosting providers. Users are advised to verify the authenticity of any Trezor-related resources by cross-referencing official domains listed on the vendor’s verified website. Organizations should monitor for newly registered domains mimicking Trezor or other cryptocurrency services, particularly those leveraging documentation platforms or content delivery networks. Security teams are encouraged to update blocklists with the provided indicators and conduct retrospective analysis to identify any prior interactions with this domain.
Data Coverage
Розвіддані з мережевої безпеки
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| OpenDNS | help-doc-trezor-suite.gitbook.io |
phishing | Phishing Block |
| DNS4EU | help-doc-trezor-suite.gitbook.io |
malicious | Sinkholed |
| DigiCert UltraDNS | help-doc-trezor-suite.gitbook.io |
malicious | Sinkholed |
| Cloudflare DNS | help-doc-trezor-suite.gitbook.io |
malicious | Sinkholed |
Процес реагування на загрози Pipeline
Перевірка за блок-листами
10 зовнішніх джерел під наглядом · знімок від 11.08.2026
Хронологія виявлення
-
Cloudflare Radar
Сканування Cloudflare Radar збережено · Відкрити сканування
Аналітика доменів
Технічні подробиціDNS, імена TLS і часові мітки
Технології
Виявлено 2 технології з високою впевненістю
Аналіз VirusTotal
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога