Author

Topic: [Be Aware] Fake Trezor (Read 271 times)

legendary
Activity: 1834
Merit: 1036
December 12, 2019, 11:05:01 PM
#13
Thank you for sharing, i always been concerned when buying a hardware wallet that the guys that work at the post office will open the wallet and install a malware or something to hack my coins, that's why i don't use it as a cold wallet
I guess this is an isolated case because what are the odds that the parcel of Trezor will be handled by a guy in the mail room that has a good knowledge of Trezor and has a readily available software to install a malware or a virus to steal the coins stored in Trezor. The chances that its an inside job is more likely to happen than that scenario in the post office.
legendary
Activity: 2366
Merit: 2054
December 12, 2019, 10:48:12 PM
#12
Fake trezor again

Be aware guys, don't search on an engine



camouflage into restaurant link
Code:
http://trekorz.ga/

Code:
IP Address: 104.24.124.30
Domain name:
TREKORZ.GA
Organisation:
Gabon TLD B.V.
My GA administrator
P.O. Box 11774
1001 GT Amsterdam
Netherlands
Phone: +31 20 5315725
Fax: +31 20 5315721




One of the most common phishing attacks in crypto is fake websites impersonating wallets, exchanges, or other services, asking unaware users to enter their recovery seed. With Trezor, you’re fully protected against remote threats, and with the right practices and a strong passphrase, you’re also safe against physical attacks targeting your recovery seed.


legendary
Activity: 2366
Merit: 2054
November 30, 2019, 07:16:49 PM
#11
Don't try put trezor to search engine, because today found fake trezor website appear and camouflage into Women's Suits Spring Summer Collection 2019 shop.




Code:
https://tkezor.tk/
https://www.virustotal.com/gui/url/4cd437b0e4d0f4ea3b4b7481cbc7367061dc2acb89441a7c02e28af1d730b90b/detection
IP Address:104.27.179.3
When we find relation that's IP will found another coin,
https://www.virustotal.com/gui/ip-address/104.27.179.3/relations
Code:
www.vdscoin.org

and fake
Code:
nordvpn.ch
http://www.fb-com.ga/
copper member
Activity: 233
Merit: 135
November 24, 2019, 08:16:23 PM
#10
After reporting it to to namecheap, the domain is now suspended as per their email.

Code:
Hello,

This is to inform you that the terezor[.]io domain was suspended. It has been placed on the clientHold status and locked to prevent modifications in our system.

Thank you for letting us know about the issue.

Nice. Namecheap should also tighten their regulations a little by at- least manually reviewing orders but at least they tend to react fast after a report is made.

A lot of these sites tend to use google ads to promote their busineses as well. It's also getting pretty hard to distinguish the urls at times (punycode attacks)

copper member
Activity: 2142
Merit: 1305
Limited in number. Limitless in potential.
November 24, 2019, 03:27:14 PM
#9
After reporting it to to namecheap, the domain is now suspended as per their email.

Code:
Hello,

This is to inform you that the terezor[.]io domain was suspended. It has been placed on the clientHold status and locked to prevent modifications in our system.

Thank you for letting us know about the issue.
hero member
Activity: 1666
Merit: 753
November 24, 2019, 05:38:44 AM
#8
Wandering what that website was doing?
1) Selling fake Trezor modified with malware or something to steal coins?
or
2) Just collecting the payment and not delivering?

Likely the second.

The capital required to develop a large scale clone of any hardware wallet is so substantial that most scammers will be unwilling or unable to put in this initial investment. It's much easier to build a phishing site from ground up and market an already existing product on it.

Either way, it's a scam. So that's that. People should be extremely careful with these phishing sites, especially in terms of hardware.
member
Activity: 294
Merit: 10
November 24, 2019, 02:57:47 AM
#7
Wandering what that website was doing?
1) Selling fake Trezor modified with malware or something to steal coins?
or
2) Just collecting the payment and not delivering?
full member
Activity: 1134
Merit: 105
November 24, 2019, 02:55:01 AM
#6
Reported it to its registrar (namecheap) so the account of this scammers and domain will be terminated.

You can either send an email to [email protected] or a better way is to raise the ticket with namecheap.
How and where can I file abuse complaints?
copper member
Activity: 2142
Merit: 1305
Limited in number. Limitless in potential.
November 24, 2019, 02:25:42 AM
#5
Reported it to its registrar (namecheap) so the account of this scammers and domain will be terminated.
legendary
Activity: 2212
Merit: 7064
November 24, 2019, 02:10:03 AM
#4
Good finding OP.
I reported fake trezor website to google and symantec.
Metamask already blacklisted it
legendary
Activity: 3136
Merit: 1172
Leading Crypto Sports Betting & Casino Platform
November 24, 2019, 02:04:46 AM
#3
Thank you for sharing, i always been concerned when buying a hardware wallet that the guys that work at the post office will open the wallet and install a malware or something to hack my coins, that's why i don't use it as a cold wallet

You should avoid the fake Trezor site only but you cannot claim that cold wallets are dangerous or avoided. If you are experienced, you will know how to protect and safely use cold wallets as they are the best way to store your coins. If you have some good amount of bitcoins it is recommended to buy hardware wallets and you can get them cheap on this black Friday.
member
Activity: 294
Merit: 10
November 23, 2019, 10:20:43 PM
#2
Thank you for sharing, i always been concerned when buying a hardware wallet that the guys that work at the post office will open the wallet and install a malware or something to hack my coins, that's why i don't use it as a cold wallet
legendary
Activity: 2366
Merit: 2054
November 23, 2019, 10:15:41 PM
#1
What Happened: Fake or Phishing Trezor Website

Phishing website :
Code:
https://terezor.io/
https://wiki.terezor.io/Welcome
https://blog.terezor.io/
https://wallet.terezor.io/





Code:
IP Address: 46.30.40.108
Domain Name: TEREZOR.IO
Registry Domain ID: D503300001182310804-LRMS
Registrar WHOIS Server: whois.namecheap.com
Registrar URL: www.namecheap.com
Updated Date: 2019-11-19T11:13:13Z
Creation Date: 2019-11-19T11:09:50Z
Registry Expiry Date: 2020-11-19T11:09:50Z
Registrar Registration Expiration Date:
Registrar: NameCheap, Inc
Registrar IANA ID: 1068




Real website: https://trezor.io/

Code:
Domain Name: TREZOR.IO
Registry Domain ID: D503300000040387472-LRMS
Registrar WHOIS Server: whois.101domain.com
Registrar URL: https://www.101domain.com
Updated Date: 2019-10-21T12:13:27Z
Creation Date: 2014-07-21T08:45:45Z
Registry Expiry Date: 2027-07-21T08:45:45Z
Registrar Registration Expiration Date:
Registrar: 101domain GRS Ltd
Registrar IANA ID: 1011
Jump to: