name-trezor-help-dvoy[.]vercel[.]app
“Deployment Unavailable”
name-trezor-help-dvoy.vercel.app — 内容不可用. 品牌冒充:Trezor; 诈骗类型:Crypto Scam. 证据摘要: VirusTotal 18/93 (ADMINUSLabs, Criminal IP, alphaMountain.ai, BitDefender, CyRadar); 2 external blocklist matches (MetaMask, SEAL); CF Radar malicious; PhishDestroy score 100/100. 注册商: Tucows.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
This domain, name-trezor-help-dvoy.vercel.app, is flagged for brand impersonation targeting Trezor, a cryptocurrency hardware wallet provider. Analysis indicates the infrastructure is designed to mimic legitimate Trezor support or recovery pages, likely aiming to harvest sensitive credentials or private keys from unsuspecting users. The domain shows no direct evidence of a crypto drainer kit at this stage, but the deployment status suggests preparatory staging or a dormant payload awaiting activation. The threat type aligns with known patterns of brand impersonation used to facilitate unauthorized access to digital asset wallets. Infrastructure analysis reveals multiple high-confidence technical indicators. The domain was registered on February 21, 2026, through Tucows Domains Inc., a registrar frequently observed in phishing campaigns due to its accessibility and bulk registration capabilities. It resolves to IP address 216.198.79.3, hosted on Amazon.com, Inc. (AS16509), a common cloud provider for malicious deployments. The SSL certificate is issued by Google Trust Services (WR1), which, while legitimate, does not mitigate the domain's fraudulent intent. VirusTotal detection shows 18 out of 95 security vendors flagging the domain, a moderate but concerning score that underscores its malicious classification. The domain appears on four security blocklists, including PhishDestroy, MetaMask, SEAL, and PhishingDB, further validating its high-risk status. Current status indicates the domain remains active, though the page title 'Deployment Unavailable' suggests either a temporary staging state or a deliberate evasion tactic to avoid detection during analysis. Response actions by security vendors have already blocked access through multiple channels, reducing immediate exposure risk. However, the domain's persistence and the registrar's historical association with malicious activity warrant continued monitoring. Users are advised to treat any communication or page associated with this domain as fraudulent. Verification of Trezor-related services should exclusively occur through official channels, and wallet recovery processes should never be initiated via third-party links or unsolicited messages.
网络安全情报
威胁响应 Pipeline
公共封禁名单状态
所用技术 · 2 identified
Cloud platform for frontend deployment, optimized for Next.js.
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
VirusTotal 分析
网站性能分析
Google PageSpeed Insights — mobile performance audit of name-trezor-help-dvoy.vercel.app · checked Mar 2, 2026
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。