Security Scan Report: welcome-trezo.vercel.app

Submitted: Sep 25, 2026, 8:50:29 PMCompleted: Sep 25, 2026, 8:52:04 PMpubliccompleted

AI Security Verdict

High Risk

Confidence: 80%

8
Risk Score

Fake Trezor.io/Start page on a Vercel subdomain impersonating the Trezor brand to push wallet software downloads; flagged as phishing. No forms, but brand impersonation and an unverified phishing report put it at HIGH_RISK.

Risk Factors (5)
Brand impersonation of Trezor (a different entity) on a non-official domain
Fake crypto wallet 'setup' page soliciting downloads of supposed Trezor Suite software
Unranked domain not present in Cisco Umbrella top 1M
Phishing threat-intel match on the primary domain (single-source, unverified)
IDS alerts for abuse of the vercel.app cloud hosting service
Domain age information unavailable

Details

Page Title

Trezor.io/Start® - Start Up Your Device® | Trezor®

Scan Type

public

Domain Name Analysis

The domain name 'welcome-trezo.vercel.app' uses the application-focused generic top-level domain (.app), featuring subdomain 'welcome-trezo'. The core label 'vercel' covers 6 characters with 2 vowels and four consonants. Tokenizing the label suggests two words: ver, cel. Median word length comes out to three characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://welcome-trezo.vercel.app/

Page Load Overview

0.98s
Total Load Time
1.2 MB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en
Text Length:4,094 chars
Detector Agreement:75%

Website Classification

Primary Category

technology software89% confidence
Type: static
Method: ml+structural

All Detected Categories

technology software
89%
cryptocurrency blockchain
76%
documentation technical
47%
finance banking
43%
education learning
42%

Detected Features

OG: article

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
364.29.17.131Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
045.43.142.7United Kingdom
AS16276OVH SAS
045.43.142.2United Kingdom
AS16276OVH SAS
0216.198.79.131Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
34--

Detected Technologies3

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T11AC1A41FF61E3726429203B6B8EA76B4FF2FC0A8925517996A2C811C63E07D181733C6

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

96:ThF6GtL69FPEJXyMwkySwl6v/p9wwt3o+mdNA6pud+XBHB3LqlGAqkaJauAV0dxc:1w+L6zcJXyyy7aBt3nw3XFuGA1VVSq8c

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:5784:CARABEnGQLlRQ0IRE9YBEQcOogAUmIBEBAQUAVNAoAgZUEHgY0gBgkSAKQAzIACKBRCOC0ACCBAIkCCQBIDQI4YEAiakAFIM

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:fc8d879fff8fffff
Perceptual Hash:be1ac2c2c34e3af1
Difference Hash:49393c249835ade2
Wavelet Hash:3c0001097f07157b
Color Hash:#408abf

Other Hashes

Crop Resistant:49393c249835ade2

Scan History

Scan history not available

Unable to load historical scan data