trzor[.]io
“SoftwaresProtect â Cloud System Protection”
证据摘要
The domain trzor.io is currently active and classified as a high‑risk brand‑impersonation campaign targeting the Trezor brand. Registration data shows the domain was created on 25 November 2023 through NameSilo, LLC, and it is hosted on the IP address 45.77.75.133, which resolves to a Vultr Holdings, LLC infrastructure in the United States. DNS resolution uses three authoritative nameservers (ns1.dnsowl.com, ns2.dnsowl.com, ns3.dnsowl.com). The site presents an HTTP 200 response and serves a TLS certificate issued by Let’s Encrypt (identifier YE1). The page title returned by the server is "SoftwaresProtect — Cloud System Protection," which does not reference the Trezor brand, indicating that the visible content has not been publicly verified beyond the title. VirusTotal analysis shows a single detection out of 91 security vendors, and the domain appears on one external blocklist, specifically PhishDestroy. No additional intelligence such as malware payloads, credential‑stealing forms, or redirection behavior is currently available. Defenders should treat trzor.io as a malicious indicator and block both the domain and its hosting IP at perimeter firewalls, DNS filters, and endpoint protection solutions. Continuous monitoring of the IP address and associated nameservers is advised, as the infrastructure could be reused for further impersonation attempts. Organizations using Trezor products should alert users to the existence of this domain and reinforce verification of official Trezor URLs.
Data Coverage
网络安全情报
威胁响应 Pipeline
阻止列表覆盖
监控中的外部数据源 10 个 · 已存快照 2026年8月12日
检测时间线
-
域名状态
可访问 → 无法访问
-
域名状态
无法访问 → 可访问
技术
识别出 3 项高置信度技术
VirusTotal 分析
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。
检查任意域名
使用存储的阻止列表、WHOIS、DNS 和公共扫描证据进行威胁分析
立即扫描举报网络钓鱼
将可疑域名提交至我们的威胁数据库——保护社区
报告实时威胁动态
最近的网络钓鱼报告和观察到的可用性变化
监控