trezorsafe5[.]com
“trezorsafe5.com”
trezorsafe5.com — Останній відомий активний (HTTP 200). Уособлення бренду: Trezor; Тип шахрайства: Crypto Drainer. Зведення доказів: VirusTotal 4/91 (alphaMountain.ai, CRDF, Gridinsoft, SOCRadar); PhishDestroy score 81/100. Реєстратор: Dynadot.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
Analysis of trezorsafe5.com as of July 28, 2026 indicates that the domain is actively hosting a crypto‑drainer operation. VirusTotal records show that four of ninety‑one scanned security vendors have flagged the site, confirming malicious behavior despite the majority of scanners returning a clean result. The HTTP response code is 200, demonstrating that the web server is reachable and serving content.
The domain is listed on a single security blocklist and has been actively blocked by the PhishDestroy mitigation service, providing additional evidence of its abusive nature. Registration information reveals that Dynadot Inc is the registrar, and the authoritative name servers are 5014.ns1.abovedomains.com and 5014.ns2.abovedomains.com, both of which are commonly associated with disposable or fast‑flux hosting patterns. No further infrastructure details such as IP address, autonomous system number, or geographic location are disclosed in the available intelligence, leaving the hosting environment partially opaque.
The lack of a published page title or brand reference limits the ability to attribute the site to a specific victim‑facing campaign, but the classification as a crypto drainer aligns with the observed indicators. Defenders should prioritize adding trezorsafe5.com to internal deny lists, enforce DNS‑level blocking where possible, and monitor network traffic for outbound connections to the domain’s resolved IPs. Continuous re‑scanning on VirusTotal and other multi‑engine platforms is advised to capture any changes in detection rates, and any observed attempts to interact with the domain should be logged for incident response.
Розвіддані з мережевої безпеки
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Аналітика доменів
Технічні деталіDNS, SAN-адреси SSL, мітки часу
ICANN OVERSIGHT
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Аналіз VirusTotal
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога