trezor-website-ram-pod-paint-sigma-gole-324324-psi[.]vercel[.]app
“Connect & Find Your Trezor”
trezor-website-ram-pod-paint-sigma-gole-324324-psi.vercel.app — Контент недоступний. Уособлення бренду: Trezor; Тип шахрайства: Crypto Scam. Зведення доказів: VirusTotal 9/95 (ADMINUSLabs, alphaMountain.ai, BitDefender, CyRadar, Fortinet); URLScan malicious verdict; PhishDestroy score 77/100. Реєстратор: Vercel.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
The domain trezor-website-ram-pod-paint-sigma-gole-324324-psi.vercel.app was registered through Vercel Inc. and resolves to the Amazon‑owned IP address 216.198.79.3, associated with ASN 16509. The site served a page titled “Connect & Find Your Trezor” and presented a TLS certificate issued by Google Trust Services under the WR1 root, indicating a valid HTTPS connection. Infrastructure analysis shows the use of Vercel hosting and the presence of HTTP Strict Transport Security (HSTS). The domain returned HTTP status 451, indicating that the content was unavailable for legal reasons, and it is currently listed as taken offline.
The site impersonates the Trezor hardware‑wallet brand and is classified as a crypto‑scam. It was blocked by the PhishDestroy blocklist and appears on a single security blocklist. VirusTotal scans recorded nine detections out of ninety‑five engines, reinforcing the malicious classification. Nameserver information is unavailable (NS_NOT_FOUND).
The evidence confirms that the domain was created to lure Trezor users into a credential‑harvesting flow, leveraging a legitimate‑looking page title and a trusted SSL certificate to increase credibility. Uncertainty remains regarding the specific payload delivered to victims, as the page content has not been captured and no visual artefacts have been disclosed. Defenders should continue to monitor the IP range owned by Amazon for similar Vercel‑hosted impersonation attempts, enforce blocklist updates to include this domain, and advise users to verify URLs against official Trezor resources. Threat intelligence feeds should flag the domain as a brand‑impersonation crypto scam, and any residual DNS entries should be purged to prevent resurrection attempts.
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Технології · 2 identified
Cloud platform for frontend deployment, optimized for Next.js.
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Аналіз VirusTotal
Архівні докази
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога