Bitcoin Forum
November 08, 2024, 07:37:39 PM *
News: Latest Bitcoin Core release: 28.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: [Be Aware] Fake Trezor  (Read 271 times)
Chikito (OP)
Legendary
*
Offline Offline

Activity: 2562
Merit: 2076


View Profile WWW
November 24, 2019, 03:15:41 AM
Merited by dkbit98 (1), The Cryptovator (1), DireWolfM14 (1)
 #1

What Happened: Fake or Phishing Trezor Website

Phishing website :
Code:
https://terezor.io/
https://wiki.terezor.io/Welcome
https://blog.terezor.io/
https://wallet.terezor.io/





Code:
IP Address: 46.30.40.108
Domain Name: TEREZOR.IO
Registry Domain ID: D503300001182310804-LRMS
Registrar WHOIS Server: whois.namecheap.com
Registrar URL: www.namecheap.com
Updated Date: 2019-11-19T11:13:13Z
Creation Date: 2019-11-19T11:09:50Z
Registry Expiry Date: 2020-11-19T11:09:50Z
Registrar Registration Expiration Date:
Registrar: NameCheap, Inc
Registrar IANA ID: 1068




Real website: https://trezor.io/

Code:
Domain Name: TREZOR.IO
Registry Domain ID: D503300000040387472-LRMS
Registrar WHOIS Server: whois.101domain.com
Registrar URL: https://www.101domain.com
Updated Date: 2019-10-21T12:13:27Z
Creation Date: 2014-07-21T08:45:45Z
Registry Expiry Date: 2027-07-21T08:45:45Z
Registrar Registration Expiration Date:
Registrar: 101domain GRS Ltd
Registrar IANA ID: 1011
fratoshi
Member
**
Offline Offline

Activity: 294
Merit: 10


View Profile
November 24, 2019, 03:20:43 AM
 #2

Thank you for sharing, i always been concerned when buying a hardware wallet that the guys that work at the post office will open the wallet and install a malware or something to hack my coins, that's why i don't use it as a cold wallet
virasog
Legendary
*
Offline Offline

Activity: 3150
Merit: 1172


Leading Crypto Sports Betting & Casino Platform


View Profile
November 24, 2019, 07:04:46 AM
 #3

Thank you for sharing, i always been concerned when buying a hardware wallet that the guys that work at the post office will open the wallet and install a malware or something to hack my coins, that's why i don't use it as a cold wallet

You should avoid the fake Trezor site only but you cannot claim that cold wallets are dangerous or avoided. If you are experienced, you will know how to protect and safely use cold wallets as they are the best way to store your coins. If you have some good amount of bitcoins it is recommended to buy hardware wallets and you can get them cheap on this black Friday.

..Stake.com..   ▄████████████████████████████████████▄
   ██ ▄▄▄▄▄▄▄▄▄▄            ▄▄▄▄▄▄▄▄▄▄ ██  ▄████▄
   ██ ▀▀▀▀▀▀▀▀▀▀ ██████████ ▀▀▀▀▀▀▀▀▀▀ ██  ██████
   ██ ██████████ ██      ██ ██████████ ██   ▀██▀
   ██ ██      ██ ██████  ██ ██      ██ ██    ██
   ██ ██████  ██ █████  ███ ██████  ██ ████▄ ██
   ██ █████  ███ ████  ████ █████  ███ ████████
   ██ ████  ████ ██████████ ████  ████ ████▀
   ██ ██████████ ▄▄▄▄▄▄▄▄▄▄ ██████████ ██
   ██            ▀▀▀▀▀▀▀▀▀▀            ██ 
   ▀█████████▀ ▄████████████▄ ▀█████████▀
  ▄▄▄▄▄▄▄▄▄▄▄▄███  ██  ██  ███▄▄▄▄▄▄▄▄▄▄▄▄
 ██████████████████████████████████████████
▄▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▄
█  ▄▀▄             █▀▀█▀▄▄
█  █▀█             █  ▐  ▐▌
█       ▄██▄       █  ▌  █
█     ▄██████▄     █  ▌ ▐▌
█    ██████████    █ ▐  █
█   ▐██████████▌   █ ▐ ▐▌
█    ▀▀██████▀▀    █ ▌ █
█     ▄▄▄██▄▄▄     █ ▌▐▌
█                  █▐ █
█                  █▐▐▌
█                  █▐█
▀▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▀█
▄▄█████████▄▄
▄██▀▀▀▀█████▀▀▀▀██▄
▄█▀       ▐█▌       ▀█▄
██         ▐█▌         ██
████▄     ▄█████▄     ▄████
████████▄███████████▄████████
███▀    █████████████    ▀███
██       ███████████       ██
▀█▄       █████████       ▄█▀
▀█▄    ▄██▀▀▀▀▀▀▀██▄  ▄▄▄█▀
▀███████         ███████▀
▀█████▄       ▄█████▀
▀▀▀███▄▄▄███▀▀▀
..PLAY NOW..
dkbit98
Legendary
*
Offline Offline

Activity: 2408
Merit: 7560



View Profile WWW
November 24, 2019, 07:10:03 AM
 #4

Good finding OP.
I reported fake trezor website to google and symantec.
Metamask already blacklisted it

█▀▀▀











█▄▄▄
▀▀▀▀▀▀▀▀▀▀▀
e
▄▄▄▄▄▄▄▄▄▄▄
█████████████
████████████▄███
██▐███████▄█████▀
█████████▄████▀
███▐████▄███▀
████▐██████▀
█████▀█████
███████████▄
████████████▄
██▄█████▀█████▄
▄█████████▀█████▀
███████████▀██▀
████▀█████████
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
c.h.
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀█











▄▄▄█
▄██████▄▄▄
█████████████▄▄
███████████████
███████████████
███████████████
███████████████
███░░█████████
███▌▐█████████
█████████████
███████████▀
██████████▀
████████▀
▀██▀▀
bL4nkcode
Copper Member
Legendary
*
Offline Offline

Activity: 2142
Merit: 1307


Limited in number. Limitless in potential.


View Profile
November 24, 2019, 07:25:42 AM
 #5

Reported it to its registrar (namecheap) so the account of this scammers and domain will be terminated.
FIFA worldcup
Full Member
***
Offline Offline

Activity: 1134
Merit: 105


View Profile WWW
November 24, 2019, 07:55:01 AM
 #6

Reported it to its registrar (namecheap) so the account of this scammers and domain will be terminated.

You can either send an email to abuse@namecheap.com or a better way is to raise the ticket with namecheap.
How and where can I file abuse complaints?
fratoshi
Member
**
Offline Offline

Activity: 294
Merit: 10


View Profile
November 24, 2019, 07:57:47 AM
 #7

Wandering what that website was doing?
1) Selling fake Trezor modified with malware or something to steal coins?
or
2) Just collecting the payment and not delivering?
magneto
Hero Member
*****
Offline Offline

Activity: 1666
Merit: 753


View Profile
November 24, 2019, 10:38:44 AM
 #8

Wandering what that website was doing?
1) Selling fake Trezor modified with malware or something to steal coins?
or
2) Just collecting the payment and not delivering?

Likely the second.

The capital required to develop a large scale clone of any hardware wallet is so substantial that most scammers will be unwilling or unable to put in this initial investment. It's much easier to build a phishing site from ground up and market an already existing product on it.

Either way, it's a scam. So that's that. People should be extremely careful with these phishing sites, especially in terms of hardware.
bL4nkcode
Copper Member
Legendary
*
Offline Offline

Activity: 2142
Merit: 1307


Limited in number. Limitless in potential.


View Profile
November 24, 2019, 08:27:14 PM
 #9

After reporting it to to namecheap, the domain is now suspended as per their email.

Code:
Hello,

This is to inform you that the terezor[.]io domain was suspended. It has been placed on the clientHold status and locked to prevent modifications in our system.

Thank you for letting us know about the issue.
trapcoder666
Copper Member
Full Member
***
Offline Offline

Activity: 234
Merit: 135



View Profile
November 25, 2019, 01:16:23 AM
 #10

After reporting it to to namecheap, the domain is now suspended as per their email.

Code:
Hello,

This is to inform you that the terezor[.]io domain was suspended. It has been placed on the clientHold status and locked to prevent modifications in our system.

Thank you for letting us know about the issue.

Nice. Namecheap should also tighten their regulations a little by at- least manually reviewing orders but at least they tend to react fast after a report is made.

A lot of these sites tend to use google ads to promote their busineses as well. It's also getting pretty hard to distinguish the urls at times (punycode attacks)

Chikito (OP)
Legendary
*
Offline Offline

Activity: 2562
Merit: 2076


View Profile WWW
December 01, 2019, 12:16:49 AM
 #11

Don't try put trezor to search engine, because today found fake trezor website appear and camouflage into Women's Suits Spring Summer Collection 2019 shop.




Code:
https://tkezor.tk/
https://www.virustotal.com/gui/url/4cd437b0e4d0f4ea3b4b7481cbc7367061dc2acb89441a7c02e28af1d730b90b/detection
IP Address:104.27.179.3
When we find relation that's IP will found another coin,
https://www.virustotal.com/gui/ip-address/104.27.179.3/relations
Code:
www.vdscoin.org

and fake
Code:
nordvpn.ch
http://www.fb-com.ga/
Chikito (OP)
Legendary
*
Offline Offline

Activity: 2562
Merit: 2076


View Profile WWW
December 13, 2019, 03:48:12 AM
 #12

Fake trezor again

Be aware guys, don't search on an engine



camouflage into restaurant link
Code:
http://trekorz.ga/

Code:
IP Address: 104.24.124.30
Domain name:
TREKORZ.GA
Organisation:
Gabon TLD B.V.
My GA administrator
P.O. Box 11774
1001 GT Amsterdam
Netherlands
Phone: +31 20 5315725
Fax: +31 20 5315721




One of the most common phishing attacks in crypto is fake websites impersonating wallets, exchanges, or other services, asking unaware users to enter their recovery seed. With Trezor, you’re fully protected against remote threats, and with the right practices and a strong passphrase, you’re also safe against physical attacks targeting your recovery seed.


nydiacaskey01
Legendary
*
Offline Offline

Activity: 1834
Merit: 1036


View Profile
December 13, 2019, 04:05:01 AM
 #13

Thank you for sharing, i always been concerned when buying a hardware wallet that the guys that work at the post office will open the wallet and install a malware or something to hack my coins, that's why i don't use it as a cold wallet
I guess this is an isolated case because what are the odds that the parcel of Trezor will be handled by a guy in the mail room that has a good knowledge of Trezor and has a readily available software to install a malware or a virus to steal the coins stored in Trezor. The chances that its an inside job is more likely to happen than that scenario in the post office.
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!