trezor-website-gules-arab-jhon-pod-paint-figma-gole-324324-psi[.]vercel[.]app
“Connect & Find Your Trezor”
trezor-website-gules-arab-jhon-pod-paint-figma-gole-324324-psi.vercel.app — 隐形 · 可达. 品牌冒充:Trezor; 诈骗类型:Brand Impersonation. 证据摘要: VirusTotal 0/94; URLScan malicious verdict; cloaking observed; PhishDestroy score 45/100. 注册商: Vercel.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
PhishDestroy identifies an active brand impersonation threat targeting Trezor users via the domain trezor-website-gules-arab-jhon-pod-paint-figma-gole-324324-psi.vercel.app. This fraudulent site exploits Trezor’s brand recognition to deceive victims into divulging sensitive wallet credentials or transferring cryptocurrency. The domain employs a deceptive naming strategy, embedding Trezor within a convoluted string of unrelated words and numbers to appear legitimate at a glance. No drainer kit signatures were detected in automated analysis, suggesting either a newly deployed or lightweight phishing toolkit. The page’s structure and potential payload remain under forensic evaluation to determine the full scope of the operation. This domain resolves to IP address 64.29.17.131 and is registered through Vercel Inc., leveraging the Vercel.app subdomain platform. Automated scans via VirusTotal currently report 0 detections out of 95 engines, indicating low immediate detection by antivirus solutions. The SSL certificate is issued by Google Trust Services, which may lend false legitimacy to users unfamiliar with domain verification processes. Google Safe Browsing (GSB) has not yet flagged this domain, and no third-party blocklist entries were detected at the time of analysis. The domain’s creation date and registrar details remain opaque due to Vercel’s privacy-preserving registration practices, complicating historical threat intelligence gathering. As of the latest assessment, this domain remains active and under investigation, with no immediate takedown action reported. Users are advised to avoid interacting with any site referencing Trezor outside of the official trezor.io domain. Security teams should monitor this domain for shifts in payload delivery or infrastructure changes, as the lack of detections suggests potential for rapid evolution. The current risk is classified as 'under_investigation' due to evolving intelligence gaps, but the active status and brand exploitation pose a credible threat to cryptocurrency holders. Immediate user action includes verifying site authenticity via official channels and reporting suspicious domains to PhishDestroy or relevant cybersecurity authorities.
威胁响应 Pipeline
公共封禁名单状态
所用技术 · 2 identified
Cloud platform for frontend deployment, optimized for Next.js.
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
VirusTotal 分析
网站性能分析
Google PageSpeed Insights — mobile performance audit of trezor-website-gules-arab-jhon-pod-paint-figma-gole-324324-psi.vercel.app · checked Apr 15, 2026
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。