gettrumpsmemes[.]vip
“Welcome to nginx!”
Zusammenfassung der Beweislage
Analysis of the domain gettrumpsmemes.vip indicates it was actively impersonating Trump Token, a cryptocurrency-related brand, as part of a brand impersonation scam. The domain was registered on August 22, 2025, through NameSilo, LLC, and resolved to the IP address 188.114.97.3, hosted on Cloudflare's network (AS13335) in the United States. The site operated without an SSL certificate, increasing the risk of unencrypted data transmission. Infrastructure analysis reveals the use of Cloudflare nameservers (david.ns.cloudflare.com and eleanor.ns.cloudflare.com), a common tactic to obscure hosting details and evade takedowns.
At the time of assessment, the domain displayed a default 'Welcome to nginx!' page title, suggesting either misconfiguration or an attempt to conceal its true content before full deployment. One security vendor flagged the domain on VirusTotal, and it appeared on a single security blocklist (PhishDestroy), confirming its classification as malicious. The Gridinsoft trust score of 0/100 further supports its high-risk status. As of July 24, 2026, the domain has been taken offline, though its prior infrastructure remains documented for defensive purposes.
Defenders should treat this domain as part of a broader pattern of Trump Token impersonation campaigns. While the exact content of the site was not fully analyzed, the combination of brand targeting, lack of SSL, and detection by security vendors justifies blocking or monitoring the domain and its associated IP. Organizations should review logs for connections to 188.114.97.3 and assess whether internal users were exposed to the site during its active period. Further investigation into the registrar (NameSilo) and hosting provider (Cloudflare) may reveal additional linked infrastructure.
Data Coverage
Erkenntnisse zur Netzwerksicherheit
Pipeline zur Reaktion auf Sicherheitsbedrohungen
Blocklistenabdeckung
10 überwachte externe Feeds · gespeicherter Stand 11.08.2026
Erkennungszeitleiste
-
Cloudflare Radar
Cloudflare-Radar-Scan gespeichert · Scan öffnen
Gespeicherte Aufnahme
Domain-Intelligenz
Technische DetailsDNS, TLS-Namen und Zeitstempel
ICANN OVERSIGHT
Akkreditierung und RAA-Kontext
Akkreditierung und RAA-Kontext
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
VirusTotal-Analyse
Wurden Sie von dieser Website betroffen?
Wenn Sie Kontoanmeldeinformationen, persönliche oder Zahlungsinformationen eingegeben oder eine Datei von dieser Domain heruntergeladen haben, ergreifen Sie sofort Maßnahmen. Nachfolgend finden Sie Ressourcen, die Ihnen helfen, den Vorfall zu melden und sich zu schützen.
Melden Sie sich bei Ihren örtlichen Behörden
Wählen Sie Ihr Land aus, um Offizielle Kontakte im Bereich Cyberkriminalität oder einen Beschwerdeentwurf erstellen → zu erhalten.
Jede beliebige Domain prüfen
Bedrohungsanalyse anhand gespeicherter Blocklisten, WHOIS, DNS und öffentlicher Scan-Beweise
Jetzt scannenPhishing melden
Melden Sie verdächtige Domains an unsere Bedrohungsdatenbank – schützen Sie die Community
MeldenEchtzeit-Bedrohungsfeed
Aktuelle Phishing-Meldungen und beobachtete Verfügbarkeitsänderungen
ÜberwachenBleiben Sie auf dem Laufenden, bleiben Sie sicher
Beobachten Sie aktuelle Bedrohungen oder legen Sie Widerspruch gegen diesen Eintrag ein, wenn Sie der Meinung sind, dass es sich um einen Fehlalarm handelt