Security Scan Report: public-trezo.vercel.app

Submitted: Sep 25, 2026, 10:51:02 PMCompleted: Sep 25, 2026, 10:52:58 PMpubliccompleted

AI Security Verdict

High Risk

Confidence: 78%

8
Risk Score

Fake 'official Trezor.io/Start' setup page on a typosquatted Vercel subdomain, impersonating SatoshiLabs/Trezor with a phishing indicator on the primary domain. No forms captured, but do not enter seed phrases or download software from it.

Risk Factors (5)
Brand impersonation of Trezor/SatoshiLabs on a non-official, typosquatted domain
Page title/meta tags falsely claim 'Official Setup' status
Primary domain flagged for phishing (Indicators of Compromise, single-source)
Free hosting subdomain with unknown, potentially very recent creation date
Domain unranked in Cisco Umbrella despite claiming a major crypto brand
Domain age information unavailable

Details

Page Title

Trezor.io/Start® | Official Setup for Trézor Wallet | Trézor®

Scan Type

public

Domain Name Analysis

The domain 'public-trezo.vercel.app' uses the application-focused generic top-level domain (.app) with subdomain 'public-trezo'. The core label 'vercel' covers 6 characters split between 2 vowels and 4 consonants. Word splitting yields two words: ver, cel. The median word length lands at three characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://public-trezo.vercel.app/

Page Load Overview

2.36s
Total Load Time
1.2 MB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en
Text Length:5,118 chars
Detector Agreement:100%

Website Classification

Primary Category

technology software61% confidence
Type: static
Method: ml+structural

All Detected Categories

technology software
61%
education learning
35%
cryptocurrency
30%
cryptocurrency blockchain
28%

Detected Features

OG: article

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
3216.198.79.3Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
045.43.142.8United Kingdom
AS16276OVH SAS
064.29.17.195Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
045.43.142.4United Kingdom
AS16276OVH SAS
34--

Detected Technologies3

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T165E1C91FF34D332501A20352B5EA7AF8AB2F80B943652A693D1D811C67A13C681777CB

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

192:1/KOhicJv1099r8RjJp7ilMWYBKUCToysQDjk3Bg5EJumRw:1/KOhim1099rq4lV3djkK5fmRw

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:7186:BdAVsSgALhAoPSmAfCLQggAQIMAZakAAAMfCJCBCAQI+EAAcBiMEBXGQJgg/OVCXGACcxRmFCkioKFIxAkAkMExaAPgCIAUD

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:0f1f3f0f3f3f5f7f
Perceptual Hash:811d3a9b3171c3e7
Difference Hash:5af8ec9ae6d89e8c
Wavelet Hash:0f0e3e023f3f0747
Color Hash:#783a62

Other Hashes

Crop Resistant:5af8ec9ae6d89e8c

Scan History

Scan history not available

Unable to load historical scan data