app-trustwebwallet[.]com
This domain is a high-risk brand impersonation site targeting users of Trust Wallet, a cryptocurrency wallet service. The site was designed to deceive visitors into believing they are interacting with the legitimate Trust Wallet platform, likely to steal login credentials, recovery phrases, or other sensitive financial information. Such impersonation attacks often employ convincing visual elements, fake login portals, or fraudulent support pages to exploit user trust and gain unauthorized access to digital assets. Analysis indicates the domain was registered on March 29, 2026, through CNOBIN INFORMATION TECHNOLOGY LIMITED, a registrar with a history of association with malicious domains. Infrastructure analysis reveals it resolved to the IP address 34.196.13.28 and was flagged by 16 out of 95 security vendors on VirusTotal. The domain appears on three security blocklists and is actively blocked by multiple threat intelligence platforms, including MetaMask and PhishDestroy. The Gridinsoft trust score of 0/100 further confirms its malicious classification. If you visited app-trustwebwallet.com or entered any information on the site, immediate action is required. Disconnect the device from the internet to prevent potential data exfiltration. Reset all passwords and recovery phrases associated with your cryptocurrency wallets using a separate, secure device. Monitor accounts for unauthorized transactions and report any suspicious activity to the legitimate service provider. Users should also scan the affected device for malware using updated security tools to detect and remove any persistent threats. Avoid reusing compromised credentials across other platforms to prevent further exposure.
Network Security Intelligence
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Hagezi Threat Feed | poetmodificative.xyz |
malicious | Sinkholed |
| Quad9 DNS | poetmodificative.xyz |
malicious | Sinkholed |
| DNS4EU | app-trustwebwallet.com |
malicious | Sinkholed |
Threat Response Pipeline
Public Blocklist Status
Stored Capture
Domain Intelligence
Technical detailsDNS, SSL SANs, timestamps
ICANN OVERSIGHT
Accreditation and RAA context
Accreditation and RAA context
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
VirusTotal Analysis
Evidence & External Reports
PD-20260329-956AE6 Recipient: abuse@ordertld.com Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive