Bitcoin Forum
May 02, 2024, 05:39:09 PM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: [WARNING]: Fake Trezor - https://login-trezor.io/  (Read 192 times)
Kemarit (OP)
Legendary
*
Offline Offline

Activity: 3066
Merit: 1352



View Profile
April 06, 2020, 01:10:10 AM
Last edit: April 06, 2020, 03:45:58 PM by Kemarit
Merited by Quickseller (3), TravelMug (2), DdmrDdmr (2), Pmalek (1)
 #1

Another tricky and malicious and obviously fake Trezor website who's intention is to steal our mnemonic phrase.

Website:
Code:
https://login-trezor.io/

What makes it more tricky is that the look and feel of the website specially the .io extension domain name. Others might think this is legit and can fall for this trap every easily.

And the funny thing is that when you click "Choose your device to continue", it will automatically ask you to enter 24 seed as compare to the real trezor website wherein it would detect first if you have a hardware wallet connected.



And the domain was registered 13 days ago.

Code:
Whois Record for Login-Trezor.io
 Domain Profile
Registrant Org WhoisGuard, Inc.
Registrant Country pa
Registrar NameCheap, Inc
IANA ID: 1068
URL: www.namecheap.com
Whois Server: whois.namecheap.com

(p)
Registrar Status serverTransferProhibited
Dates 13 days old
Created on 2020-03-23
Expires on 2021-03-23
Updated on 2020-03-23

http://whois.domaintools.com/login-trezor.io

Archive here

▄▄███████▄▄
▄██████████████▄
▄██████████████████▄
▄████▀▀▀▀███▀▀▀▀█████▄
▄█████████████▄█▀████▄
███████████▄███████████
██████████▄█▀███████████
██████████▀████████████
▀█████▄█▀█████████████▀
▀████▄▄▄▄███▄▄▄▄████▀
▀██████████████████▀
▀███████████████▀
▀▀███████▀▀
.
 MΞTAWIN  THE FIRST WEB3 CASINO   
.
.. PLAY NOW ..
"You Asked For Change, We Gave You Coins" -- casascius
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
1714671549
Hero Member
*
Offline Offline

Posts: 1714671549

View Profile Personal Message (Offline)

Ignore
1714671549
Reply with quote  #2

1714671549
Report to moderator
Chikito
Legendary
*
Offline Offline

Activity: 2380
Merit: 2054



View Profile WWW
April 06, 2020, 06:08:38 AM
Merited by Quickseller (3)
 #2

I see the relationship that's IP
https://www.virustotal.com/gui/ip-address/217.107.219.186/relations
Code:
www.wallet-trezor.io



A scammer usually use same trick and domain.

.
.BLACKJACK ♠ FUN.
█████████
██████████████
████████████
█████████████████
████████████████▄▄
░█████████████▀░▀▀
██████████████████
░██████████████
████████████████
░██████████████
████████████
███████████████░██
██████████
CRYPTO CASINO &
SPORTS BETTING
▄▄███████▄▄
▄███████████████▄
███████████████████
█████████████████████
███████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
███████████████████████
█████████████████████
███████████████████
▀███████████████▀
█████████
.
UserU
Hero Member
*****
Offline Offline

Activity: 2030
Merit: 531


FREE passive income eBook @ tinyurl.com/PIA10


View Profile WWW
April 06, 2020, 06:21:56 AM
 #3

Good job with the find. The domain looks pretty legit with the SSL and I wonder how many might have fallen victim to this within the past 13 days.

.
.500 CASINO.██

  ▄

.
THE HOTTEST CRYPTO
CASINO & SPORTSBOOK
         ▄▄▄███████████
 ▄▄▄████████████████

▐████████████████████
 ██████████████████
 ▐██████████████████
 ▐█████████████████
  ██████████████████
  ██████▀█████▀█████
  ▐████████████████
  ▐██████████████
   █████████████████
   ▐██████████████████
    ▀██████▀▀▀▀▀▀   ▀▀▀█
▄▄▄▀▀▀▀▀▀▀▄▄▄
▄▄▀▀▄ ▄ ▀ ▀ ▀ ▄ ▄▀▀▄▄
▄▀▄ ▀               ▀ ▄▀▄
█ ▄                     ▄ █
█ ▄  █████  ▄███▄  ▄███▄  ▄ █
█ ▄   ██▄▄   ██ ██  ██ ██   ▄ █
█ ▄   ▀▀▀██  ██ ██  ██ ██   ▄ █
█ ▄   ▄▄ ██  ██ ██  ██ ██   ▄ █
█ ▄  ▀███▀  ▀███▀  ▀███▀  ▄ █
█ ▄                     ▄ █
▀▄ ▀ ▄             ▄ ▀ ▄▀
▀▀▄▄ ▀ ▄ ▄ ▄ ▄ ▀ ▄▄▀▀
▀▀▀▄▄▄▄▄▄▄▀▀▀

▄▄▄██████████▄▄▄
████████▀██▀▀██▄▄
 █
█████████████████▄
 █
████████████████████
  █
██▄████▄███████▄███
  █
████████████████████
  █
███▀████▀███████▀███
 █
████████████████████
 █
█████████████████▀
█████████▄██▄▄██▀▀
 ▀▀▀██████████▀▀▀

ORIGINALS

SLOTS

LIVE GAMES

SPORTSBOOK



.
██..PLAY NOW..
xxjumperxx
Sr. Member
****
Offline Offline

Activity: 504
Merit: 265

Buy Bitcoin!


View Profile
April 06, 2020, 06:35:27 AM
 #4

Wow thanks for the heads-up!
They made it look really good and a newbie could and would certainly fall for a scam like this!

 I certainly hope that nobody has fallen for it!
Kaliecious
Full Member
***
Offline Offline

Activity: 246
Merit: 100



View Profile
April 06, 2020, 01:06:26 PM
 #5

thank you, very useful information for trezor users. they must be careful to log in to their account
now a lot of phishing webs are popping up to steal user data

Lucius
Legendary
*
Offline Offline

Activity: 3234
Merit: 5634


Blackjack.fun-Free Raffle-Join&Win $50🎲


View Profile WWW
April 06, 2020, 02:07:12 PM
 #6

All the wisdom needed to avoid this kind of thing is that every hardware wallet user realizes that he is not typing his seed words anywhere but the device itself. Any website, extension, plugin, or person on social networking site that asks you to type in your seed is a pretty obvious sign that it's a scam.

In addition, keep legitimate web pages with your bookmarks and always access them in this way with additional verification. If you are using a search engine, avoid Google Search or use Firefox with uBlock Origin to block Google Ads.

.
.BLACKJACK ♠ FUN.
█████████
██████████████
████████████
█████████████████
████████████████▄▄
░█████████████▀░▀▀
██████████████████
░██████████████
████████████████
░██████████████
████████████
███████████████░██
██████████
CRYPTO CASINO &
SPORTS BETTING
▄▄███████▄▄
▄███████████████▄
███████████████████
█████████████████████
███████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
███████████████████████
█████████████████████
███████████████████
▀███████████████▀
█████████
.
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!