MALICIOUS — CRITICAL
tw-order[.]live
14 of 91 security engines flagged the domain; 2 public blocklists listed it (MetaMask, SEAL); the latest stored check returned HTTP 502.
- VirusTotal
- 14/91
- Blocklists
- 2 · MetaMask, SEAL
- التوفر
- المحتوى غير متوفر · HTTP 502
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
tw-order.live — المحتوى غير متوفر (HTTP 502). انتحال العلامة التجارية: Trust Wallet; نوع الاحتيال: Crypto Scam. ملخص الأدلة: VirusTotal 14/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, CRDF); URLScan malicious verdict; Spamhaus DBL_PHISH; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 95/100. مسجّل النطاق: NiceNIC.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
Evidence Digest
tw-order.live is classified critical with an evidence score of 95/100. 14 of 91 security engines flagged the domain; 2 public blocklists listed it (MetaMask, SEAL). Registered 29 Apr 2026 via NICENIC INTERNATIONAL GROUP CO., LIMITED, hosted on 188.114.97.3 (Cloudflare, Inc., CA). The latest stored check on 9 Aug 2026 returned HTTP 502 and includes a capture. 1 outgoing abuse report is recorded, most recently on 30 Apr 2026.
Stored generated summary (templated)openai · 07/07/2026
Retained for the record. This text repeats stored detection facts and is not presented as authored analysis.
This domain, tw-order.live, operates as a phishing site specifically targeting users of Trust Crypto Card, a cryptocurrency payment service. The site employs deceptive branding and design elements to trick visitors into entering sensitive credentials, such as wallet private keys, recovery phrases, or personal identification details. The intent is to harvest this information for unauthorized access to cryptocurrency accounts or financial fraud. Analysis of the page title, "Trust Crypto Card | Crypto Card," confirms the impersonation of the legitimate service, increasing the likelihood of successful social engineering attacks against unsuspecting users. Infrastructure analysis reveals multiple high-risk indicators. The domain was registered on April 29, 2026, through NICENIC INTERNATIONAL GROUP CO., LIMITED, a registrar frequently associated with malicious domains. It resolves to the IP address 188.114.97.3 and is flagged by 14 out of 95 security vendors on VirusTotal, including detections for phishing and fraudulent activity. Additionally, the domain appears on three security blocklists, and its Gridinsoft trust score is 0/100, further confirming its malicious nature. Technologies detected on the site include Vue.js for dynamic content rendering, Facebook Pixel for tracking user interactions, and Cloudflare for content delivery and DDoS protection, which may obscure the true origin of the malicious activity. Users who have visited tw-order.live or interacted with its content should take immediate action to mitigate potential risks. First, disconnect any wallets or accounts linked to the site and revoke any suspicious permissions granted. Conduct a full scan of the device using updated security tools to detect and remove any malware or unwanted software. Monitor cryptocurrency wallets and financial accounts for unauthorized transactions, and report any suspicious activity to the relevant platform. If credentials were entered, reset passwords and enable multi-factor authentication where possible. Avoid clicking on links from untrusted sources and verify the legitimacy of any cryptocurrency-related communications before taking action.
نطاق تغطية البيانات12 recorded checks
استخبارات أمن الشبكات Registrar context
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
لقطة محفوظة
معلومات النطاق
التفاصيل الفنيةDNS، أسماء المجال البديلة (SAN) في بروتوكول SSL، الطوابع الزمنية
ICANN OVERSIGHT
الاعتماد وسياق RAA
الاعتماد وسياق RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Latest Classified Outcome 2026-08-09 01:46:16 UTC
التقنيات · 5 identified
Vue.js is an open-source model–view–viewmodel JavaScript framework for building user interfaces and single-page applications.
vuejs.org ثقة 100٪Facebook pixel is an analytics tool that allows you to measure the effectiveness of your advertising.
facebook.com ثقة 100٪Cloudflare Browser Insights is a tool that measures the performance of websites from the perspective of users.
www.cloudflare.com ثقة 100٪Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com ثقة 100٪HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org ثقة 100٪تحليل VirusTotal
تحليل أداء الموقع
Google PageSpeed Insights — mobile performance audit of tw-order.live · checked Jun 26, 2026
الأدلة والتقارير الخارجيةIndependent lookups and source reports
“Suspected Trust Wallet brand impersonation / cryptocurrency scam landing page. Reported domain: tw-order.live. Reported URL: https://tw-order.live/?utm_medium=paid&utm_source=ig&utm_id=120245694289440503&utm_content=120245694658300503&utm_term=120245694658210503&utm_campaign=120245694289440503&fbclid=PAdGRleARgFp1leHRuA2FlbQEwAGFkaWQBqzLSfb_Dh3NydGMGYXBwX2lkDzEyNDAyNDU3NDI4NzQxNAABp6hj32fprIHEphIq_YMm98ycqW28qdlVzi4iOD5AhEETx2rkZM8tsffw7_kw_aem_OpLDG-RHtpieOfuFsQbCgA. Reported path/query: /?utm_”
PD-20260430-B0D8CE Recipient: abuse@nicenic.net, abuse@identitydigital.com Victim safety and official reportingImmediate actions and verified reporting channels
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.