trust-wweb3-extension[.]created[.]app
“Trust Wallet Extension - Secure Your Crypto”
Zusammenfassung der Beweislage
The domain trust-wweb3-extension.created.app was registered on February 21, 2026 through Tucows Domains Inc. and is currently listed as offline. Host resolution points to IP address 216.150.1.129, which belongs to Amazon.com, Inc. AS16509 and is geolocated in the United States. The site presents a TLS certificate issued by Let’s Encrypt (R13) and serves HTTP 404 responses, indicating the landing page is not delivering content at the time of analysis. The page title retrieved from the host is “Trust Wallet Extension - Secure Your Crypto,” directly targeting the Trust Wallet brand and matching the reported scam type of a crypto‑related impersonation.
Technical fingerprints show the use of Node.js, React, Next.js, Vercel hosting, Google Cloud services, LaunchDarkly feature flags, HSTS and Google Cloud CDN, consistent with a modern web application stack. The domain appears on one security blocklist and has been blocked by PhishDestroy, confirming that at least one reputable anti‑phishing service has taken remedial action. Gridinsoft assigns a trust score of 0 out of 100, reflecting extreme suspicion. VirusTotal scans report four of ninety‑three security vendors flagging the domain, providing additional independent confirmation of malicious intent.
While the site currently returns a 404, the combination of brand‑targeted page title, low trust score, blocklist presence, and vendor detections strongly suggests an active crypto‑scam infrastructure that was recently taken down. Defenders should continue to monitor the domain and associated IP for any re‑appearance, enforce blocking of the domain in corporate web filters, and educate users about unsolicited Trust Wallet extension prompts. Incident response teams should also review related Vercel and Google Cloud DNS records for potential spill‑over assets, and consider sharing the indicator set with threat‑intelligence sharing platforms to aid broader community protection.
Momentaufnahme der übermittelten Beweise
- Gesendet
- Protokolleinträge
- 1
- Fall-ID
PD-20260125-D2DBEA- PDF-Artefakt
- PDF-Beweis
Rechtsgrundlage
Vollständiger Beweistext
Acceptable Use Policy (AUP): The domain trust-wweb3-extension.created.app is engaged in phishing activities, which directly contravenes your AUP prohibiting illegal activities and deception.
Terms of Service (TOS): The use of this domain for fraudulent purposes constitutes a violation of your TOS, which reserves the right to suspend or terminate services for such infractions.
Applicable Laws (Unknown):
Computer Fraud and Abuse Act (CFAA): This U.S. federal law prohibits unauthorized access to computers and networks, which is applicable to phishing schemes.
Wire Fraud Statute (18 U.S.C. § 1343): This law criminalizes schemes to defraud individuals or entities via electronic communications, including phishing.
Anti-Phishing Act (15 U.S.C. § 7704): This act prohibits the use of misleading domain names and deceptive practices in commercial electronic mail messages.
Regulatory Note: Failure to take immediate action against this domain may expose your organization to liability under applicable laws and could result in regulatory scrutiny. It is imperative to act swiftly to mitigate risks associated with domain abuse.
Data Coverage
Pipeline zur Reaktion auf Sicherheitsbedrohungen
Blocklistenabdeckung
10 überwachte externe Feeds · gespeicherter Stand 13.08.2026
Erkennungszeitleiste
-
Cloudflare Radar
Cloudflare-Radar-Scan gespeichert · Scan öffnen
-
VirusTotal
4 → 5
Gespeicherte Aufnahme
Domain-Intelligenz
Technische DetailsDNS, TLS-Namen und Zeitstempel
ICANN OVERSIGHT
Registration: created.app
Akkreditierung und RAA-Kontext
Akkreditierung und RAA-Kontext
Registrar accreditation and DNS abuse obligations
For the registrable domain created.app behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Technologien
9 Technologien mit hoher Konfidenz erkannt
VirusTotal-Analyse
Website-Performanceanalyse
Google PageSpeed Insights — mobile performance audit of trust-wweb3-extension.created.app · checked Mar 2, 2026
Wurden Sie von dieser Website betroffen?
Wenn Sie Kontoanmeldeinformationen, persönliche oder Zahlungsinformationen eingegeben oder eine Datei von dieser Domain heruntergeladen haben, ergreifen Sie sofort Maßnahmen. Nachfolgend finden Sie Ressourcen, die Ihnen helfen, den Vorfall zu melden und sich zu schützen.
Melden Sie sich bei Ihren örtlichen Behörden
Wählen Sie Ihr Land aus, um Offizielle Kontakte im Bereich Cyberkriminalität oder einen Beschwerdeentwurf erstellen → zu erhalten.
Jede beliebige Domain prüfen
Bedrohungsanalyse anhand gespeicherter Blocklisten, WHOIS, DNS und öffentlicher Scan-Beweise
Jetzt scannenPhishing melden
Melden Sie verdächtige Domains an unsere Bedrohungsdatenbank – schützen Sie die Community
MeldenEchtzeit-Bedrohungsfeed
Aktuelle Phishing-Meldungen und beobachtete Verfügbarkeitsänderungen
ÜberwachenBleiben Sie auf dem Laufenden, bleiben Sie sicher
Beobachten Sie aktuelle Bedrohungen oder legen Sie Widerspruch gegen diesen Eintrag ein, wenn Sie der Meinung sind, dass es sich um einen Fehlalarm handelt