help-trezorhdwlare[.]gitbook[.]io
Зведення доказів
The domain help-trezorhdwlare.gitbook.io has been confirmed as a brand impersonation resource specifically targeting Trezor cryptocurrency wallet users. Analysis indicates this infrastructure was designed to mimic legitimate Trezor support documentation and interfaces, presenting an elevated risk of credential harvesting or cryptocurrency theft. The domain is currently offline, though prior activity suggests it may reappear under modified infrastructure. Infrastructure analysis reveals the domain resolved to IP address 104.18.40.47, geolocated to Cloudflare, Inc. in Canada. The resource was flagged by 16 of 95 security vendors on VirusTotal, with detection labels including phishing and brand impersonation. Registration occurred through GitBook, a platform commonly exploited for hosting malicious documentation due to its perceived legitimacy. The domain appears on one security blocklist, and its SSL certificate was issued by Google Trust Services (WE1). Creation date records indicate the domain was established on April 26, 2026, though this timestamp may reflect platform-specific registration rather than traditional WHOIS data. Current status indicates the domain has been taken offline, though the underlying threat remains active. Organizations and individuals are advised to monitor for reemergence under similar naming conventions or alternative hosting platforms. Users who accessed this domain should immediately rotate credentials for any associated cryptocurrency wallets or services. Security teams should update detection rules to include the observed IP address and certificate authority details. Given the targeted nature of this campaign, heightened vigilance is recommended for Trezor-related communications, particularly those hosted on third-party documentation platforms.
Data Coverage
Розвіддані з мережевої безпеки
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DigiCert UltraDNS | help-trezorhdwlare.gitbook.io |
malicious | Sinkholed |
Процес реагування на загрози Pipeline
Перевірка за блок-листами
10 зовнішніх джерел під наглядом · знімок від 12.08.2026
Хронологія виявлення
-
Cloudflare Radar
Сканування Cloudflare Radar збережено · Відкрити сканування
Аналітика доменів
Технічні подробиціDNS, імена TLS і часові мітки
Технології
Виявлено 2 технології з високою впевненістю
Аналіз VirusTotal
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога