trezor-data[.]gxtigroup[.]com
“Index of /”
trezor-data.gxtigroup.com — 内容不可用. 品牌冒充:Trezor; 诈骗类型:Crypto Scam. 证据摘要: VirusTotal 11/93 (alphaMountain.ai, BitDefender, CyRadar, ESET, Forcepoint ThreatSeeker); PhishDestroy score 83/100.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
The domain trezor-data.gxtigroup.com was observed being used in a brand‑impersonation campaign targeting the cryptocurrency hardware wallet provider Trezor. VirusTotal records show that 11 of 93 scanned security vendors flagged the domain as malicious, indicating a moderate level of detection across the ecosystem. The site was registered on 21 February 2026 and, at the time of analysis (23 July 2026), the host has taken the service offline. PhishDestroy listed the domain on its blocklist, and the domain also appears on a single external security blocklist, reinforcing the view that it was actively being used for malicious purposes.
The SSL certificate presented is identified as “R12”, a detail that aligns with typical short‑lived certificates used by transient phishing infrastructure. Gridinsoft assigned a trust score of 0 out of 100, the lowest possible rating, further confirming the domain’s lack of legitimacy. The HTTP response returned the generic page title “Index of /”, which provides no functional content but is consistent with a placeholder page often employed to hide malicious payloads. The campaign has been classified as a crypto‑scam, and the domain explicitly impersonates the Trezor brand, suggesting that victims may have been directed to submit wallet credentials or seed phrases.
Because the hosting IP, registrar, and ASN information were not disclosed in the available intelligence, the full infrastructure footprint remains partially unknown. Defenders should ensure that the domain is added to DNS and URL filtering blocklists, monitor for any residual traffic to the associated IP ranges, and update incident response playbooks to include Trezor‑related impersonation indicators. Continuous re‑evaluation is advised in case the domain is re‑hosted or the underlying infrastructure is reused in future campaigns.
威胁响应 Pipeline
公共封禁名单状态
取证情报
VirusTotal 分析
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。