trez-sute[.]wixstudio[.]com
“Official Trezor™ Suite — Desktop & Web App for Hardware Wallets”
trez-sute.wixstudio.com — Контент недоступний. Уособлення бренду: Trezor; Тип шахрайства: Brand Impersonation. Зведення доказів: VirusTotal 4/91 (alphaMountain.ai, Cluster25, ESET, Gridinsoft); 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 66/100. Реєстратор: GoDaddy.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
Analysis of trez-sute.wixstudio.com shows a clear pattern of brand impersonation targeting Trezor users. The site was registered through GoDaddy.com, LLC on December 17, 2016 and is currently hosted on an IP address owned by Google LLC (34.144.206.118, AS396982, United States). The TLS certificate is issued by Let’s Encrypt (R13) and the server presents HSTS, HTTP/3, and Google Cloud CDN, indicating a modern web stack. Detected technologies include Wix, React, Lodash, and Google Cloud, consistent with a typical Wix‑based site.
The page title returned by the server reads "Official Trezor™ Suite — Desktop & Web App for Hardware Wallets," directly referencing the Trezor brand and reinforcing the impersonation claim. The HTTP response code is 404, suggesting the content is no longer reachable; however, the domain remains listed on three security blocklists and has been actively blocked by PhishDestroy, MetaMask, and SEAL. VirusTotal scans report that four of ninety‑one security vendors flagged the domain, providing additional corroboration of malicious intent. While the site is offline, its infrastructure remains under the control of the malicious actor, and the domain could be reactivated with similar content.
Defenders should continue to block the domain at perimeter and endpoint layers, monitor DNS queries for the associated nameservers (dns1.p08.nsone.net through dns4.p08.nsone.net), and consider adding the IP address to threat intelligence feeds. Ongoing surveillance of the registrar’s activity and periodic re‑scans with VirusTotal are advisable to detect any future changes. The combination of brand‑specific page title, blocklist presence, and vendor detections makes trez-sute.wixstudio.com a high‑confidence Trezor brand impersonation threat despite its current offline status.
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Збережений знімок
Аналітика доменів
Технічні деталіDNS, SAN-адреси SSL, мітки часу
ICANN OVERSIGHT
Registration: wixstudio.com
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For the registrable domain wixstudio.com behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Технології · 7 identified
Wix provides cloud-based web development services, allowing users to create HTML5 websites and mobile sites.
www.wix.com 100% впевненостіReact is an open-source JavaScript library for building user interfaces or UI components.
reactjs.org 100% впевненостіLodash is a JavaScript library which provides utility functions for common programming tasks using the functional programming paradigm.
www.lodash.com 100% впевненостіHTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 100% впевненостіCloud CDN uses Google's global edge network to serve content closer to users.
cloud.google.com 100% впевненостіHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% впевненостіАналіз VirusTotal
Докази та зовнішні звіти
PD-20260620-C0AD4C Recipient: abuse@godaddy.com Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога