trezior-hardware-live[.]vercel[.]app
“Trézor.io/Start® | Starting Up Your Device - Trézor®”
trezior-hardware-live.vercel.app — Контент недоступний. Уособлення бренду: Trezor; Тип шахрайства: Crypto Scam. Зведення доказів: VirusTotal 15/95 (ADMINUSLabs, Criminal IP, alphaMountain.ai, BitDefender, CyRadar); URLScan malicious verdict; CF Radar malicious; PhishDestroy score 95/100. Реєстратор: Vercel.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
Analysis of trezior-hardware-live.vercel.app as of July 25, 2026 shows that the site was used to impersonate the hardware‑wallet brand Trezor. The page title returned by the server, “Trézor.io/Start® | Starting Up Your Device - Trézor®”, directly references the legitimate Trezor brand, confirming a brand‑impersonation tactic. The domain is hosted on Vercel infrastructure and serves content over HTTPS with a Google Trust Services / WR1 certificate, indicating a valid TLS chain but offering no assurance of legitimacy. HTTP response code 451 signals that the content was unavailable due to legal reasons, consistent with the reported “taken offline” status. DNS resolution points to IP 64.29.17.67, which belongs to Amazon.com, Inc. (AS16509) in the United States, a common hosting provider for disposable phishing sites.
The site employed HSTS, a standard security header, but this does not mitigate the underlying impersonation. VirusTotal scans flagged the domain by 15 of 95 security vendors, and the domain appears on at least one external blocklist, confirming that multiple security engines consider it malicious. PhishDestroy has also listed the site as blocked. The registrar information shows the domain was registered through Vercel Inc., a platform that allows rapid deployment of short‑lived domains.
No nameserver data were returned, and the domain is currently offline, limiting immediate observation of payloads. Defenders should continue to block the domain at network and email gateways, ensure that any URL filtering solutions reference the observed blocklist entries, and monitor for additional domains that use the same Vercel‑based deployment pattern targeting Trezor users. Threat intelligence feeds should be updated with the observed indicators—domain name, IP address, SSL certificate fingerprint, and HTTP 451 response—to support rapid detection of re‑hosted copies.
Розвіддані з мережевої безпеки
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Технології · 2 identified
Vercel is a cloud platform for static frontends and serverless functions.
vercel.com 100% впевненостіHTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 100% впевненостіАналіз VirusTotal
Архівні докази
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога