EN ES PT
Back to Stats

Captura Visual

Screenshot of start-io-trezor.stormkit.dev

Información de Detección

https://start-io-trezor.stormkit.dev/
Detected Brand
Trezor
Country
International
Confianza
95%
HTTP Status
200
Report ID
5688e54b-3c0…
Analyzed
2026-02-03 23:45

Hashes de Contenido (Similitud HTML)

Used to detect similar phishing pages based on HTML content

Algorithm Hash Value
CONTENT TLSH
T10862665D774A33314E6302C15A58A7D9A736F38453621EC1B04A81F4DFAF9F3B422B88
CONTENT ssdeep
192:s1+81pjiwC4NPPjIJugKMZx9bNb8mTxNxNrM7kxdZf6278d6vg7KZeLpyz96oaQ9:u++mAedriwOxTeqcbD4T9dlASwl

Hashes Visuales (Similitud de Captura)

Used to detect visually similar phishing pages based on screenshots

Algorithm Hash Value
VISUAL pHash
9d90b7e5dae041ac
VISUAL aHash
ff1e18181800ffbf
VISUAL dHash
9cbcbbf176d63679
VISUAL wHash
ff0e18180860ff9f
VISUAL colorHash
16c10000000
VISUAL cropResistant
0020108e8636083c,ba0052a484d200be,636a46d6e4bcd97a,b4a4d4d8f4a57676,8b83703c69f0b2aa,c0a28a371382a2c4,a282cc4b1355a2a2,3600736763797d79,078080b0b0b0b0b0,bc3cbbf17136d6b6,4b174f7f7fffffef,333f4fc3d1d4d0d0

Análisis de Código

Risk Score 50/100
Nivel de Amenaza ALTO
⚠️ Phishing Confirmed
🎣 Banking

🔬 Threat Analysis Report

• Amenaza: Suplantación de identidad
• Objetivo: Trezor
• Método: Suplantación de dominio en un servicio de alojamiento gratuito
• Exfil: Probablemente apunta a robar credenciales de inicio de sesión o redirigir a otra página de phishing.
• Indicadores: Dominio no coincidente, alojamiento gratuito.
• Riesgo: ALTO

📊 Desglose de Puntuación de Riesgo

Total Risk Score
90/100

Contributing Factors

Domain Mismatch
The domain is not the official Trezor domain and is hosted on a suspicious free hosting service.
Hosting Provider
Free Hosting is a common tactic for phishing websites.

🔬 Análisis Integral de Amenazas

Tipo de Amenaza
Banking Credential Harvester
Objetivo
Trezor users (International)
Método de Ataque
Brand impersonation
Canal de Exfiltración
Form submission (backend endpoint not detected - likely JavaScript-based)
Evaluación de Riesgo
MEDIUM - Automated credential harvesting with Form submission (backend endpoint not detected - likely JavaScript-based)

⚠️ Indicators of Compromise

  • Kit types: Banking

🏢 Análisis de Suplantación de Marca

Impersonated Brand
Trezor
Official Website
https://trezor.io
Fake Service
Trezor Wallet or Trezor website

⚔️ Metodología de Ataque

Primary Method: Impersonation (Brand)

The attacker creates a website that closely resembles the legitimate Trezor website to deceive users into providing sensitive information or installing malware.

Secondary Method: Domain Spoofing

The attacker uses a similar-looking domain to trick users into believing they are on the real website.

🌐 Indicadores de Compromiso de Infraestructura

Domain Information

Dominio
start-io-trezor.stormkit.dev
Registered
Unknown
Registrar
Unknown
Estado
Inactive

🤖 AI-Extracted Threat Intelligence

😰
"Nunca pensé que me pasaría a mí"
Esto dicen las 2.3 millones de víctimas cada año. No esperes a ser una estadística.