auth-public-trezor-sso[.]typedream[.]app
“Trezor® Hardware® - Wallet | Getting Started”
auth-public-trezor-sso.typedream.app — 内容不可用. 品牌冒充:Trezor; 诈骗类型:Brand Impersonation. 证据摘要: VirusTotal 11/91 (ChainPatrol, alphaMountain.ai, BitDefender, CyRadar, ESET); URLScan malicious verdict; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 83/100. 注册商: Typedream.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
This domain, auth-public-trezor-sso.typedream.app, is flagged as a high-risk brand impersonation threat targeting Trezor, a cryptocurrency hardware wallet provider. Analysis indicates the site mimics Trezor’s single sign-on (SSO) infrastructure, presenting a fraudulent login interface designed to harvest user credentials. The page title, 'Trezor® Hardware® - Wallet | Getting Started,' reinforces the deception by replicating official branding, increasing the likelihood of successful phishing attempts against Trezor users. Technical indicators confirm the domain’s malicious intent. VirusTotal reports 3 out of 95 security vendors have flagged the domain, a low but notable detection rate suggesting targeted or evasive tactics. The domain is registered through Typedream, a platform often abused for rapid phishing site deployment. Infrastructure analysis reveals it resolves to IP address 188.114.97.3, a Cloudflare-associated endpoint commonly used to obfuscate hosting origins. The SSL certificate is issued by Google Trust Services, providing a false sense of legitimacy. No creation date is publicly available, and Google Safe Browsing (GSB) status remains unconfirmed, though the domain is not widely blocklisted at this time. The domain remains active as of the latest verification, posing an ongoing risk to Trezor users. Response actions should include immediate blacklisting by security providers, takedown requests to Typedream, and DNS sinkholing for the resolved IP. Users are advised to verify domain authenticity via official Trezor channels before entering credentials. The remaining risk is classified as high due to the domain’s active status, targeted brand impersonation, and low detection rate, which may delay widespread mitigation efforts.
威胁响应 Pipeline
公共封禁名单状态
VirusTotal 分析
存档证据
网站性能分析
Google PageSpeed Insights — mobile performance audit of auth-public-trezor-sso.typedream.app · checked Jun 26, 2026
网站配置分析
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。