MALICIOUS — CRITICAL
tcard[.]fi
12 of 91 security engines flagged the domain; 2 public blocklists listed it (MetaMask, SEAL); the latest stored check returned HTTP 502.
- VirusTotal
- 12/91
- Blocklists
- 2 · MetaMask, SEAL
- التوفر
- المحتوى غير متوفر · HTTP 502
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
tcard.fi — المحتوى غير متوفر (HTTP 502). انتحال العلامة التجارية: Apple; نوع الاحتيال: Crypto Drainer. ملخص الأدلة: VirusTotal 12/91 (alphaMountain.ai, BitDefender, Chong Lua Dao, CyRadar, Forcepoint ThreatSeeker); 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 86/100. مسجّل النطاق: Key-Systems.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
Evidence Digest
tcard.fi is classified critical with an evidence score of 86/100. 12 of 91 security engines flagged the domain; 2 public blocklists listed it (MetaMask, SEAL). Registered 20 Apr 2026 via Key-Systems GmbH, hosted on 216.150.1.1 (Amazon.com, Inc., US). The latest stored check on 9 Aug 2026 returned HTTP 502 and includes a capture. 1 outgoing abuse report is recorded, most recently on 19 Apr 2026.
Stored generated summary (templated)mistral · 20/04/2026
Retained for the record. This text repeats stored detection facts and is not presented as authored analysis.
PhishDestroy identifies tcard.fi as a domain actively involved in generic phishing attacks. Current investigations classify the threat as active and under review, with no confirmed brand impersonation at this time.
This domain was flagged by 0 of 95 VirusTotal vendors as of the latest scan, indicating minimal detection despite its malicious activity. The domain was registered through Key-Systems GmbH, resolved to IP 216.150.1.1, and was created on April 19, 2026. No blocklist entries were found, and the domain holds a Let's Encrypt SSL certificate. Trust scores remain unverified due to limited threat intelligence.
At this stage, users are advised to avoid interacting with tcard.fi until further analysis is completed. Security teams should monitor outbound connections to 216.150.1.1 and block the domain at the network level. Additionally, users should validate the legitimacy of any crypto-related platforms via PhishDestroy before entering credentials or transferring funds.
نطاق تغطية البيانات12 recorded checks
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
التقنيات · 4 identified
Cloud platform for frontend deployment, optimized for Next.js.
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Conversion-tracking pixel by Meta — logs page views and custom events to Facebook/Instagram ad accounts.
www.facebook.comتحليل VirusTotal
تحليل أداء الموقع
Google PageSpeed Insights — mobile performance audit of tcard.fi · checked Apr 20, 2026
الأدلة والتقارير الخارجيةIndependent lookups and source reports
PD-20260419-1AA418 Recipient: abuse@vercel.com Victim safety and official reportingImmediate actions and verified reporting channels
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.