# f.gettrustpayment.live — SUSPICIOUS > f.gettrustpayment.live is a crypto drainer phishing site with 0/95 VirusTotal detections. Avoid entering wallet details here. ## Summary PhishDestroy identifies f.gettrustpayment.live as an active crypto drainer posing as a payment portal. The site mimics legitimate trust-payment services to trick users into approving malicious cryptocurrency transactions that drain wallet funds without consent. Visitors risk losing entire digital asset balances if wallet connections or credential submissions are authorized. This domain is under active investigation due to confirmed malicious intent, though antivirus engines have not yet flagged it. This domain was flagged by PhishDestroy security teams and resolves to IP address 185.246.190.216, hosted on infrastructure associated with fraudulent cryptocurrency schemes. The site uses a Let’s Encrypt SSL certificate to appear legitimate, but the domain was registered recently and currently maintains 0 detections across 95 VirusTotal engines as of tracking seed ac3373. The lack of detections does not indicate safety—many crypto drainers evade detection until reports escalate post-victimization. If you visited f.gettrustpayment.live, disconnect any connected wallets immediately through your wallet app’s connection manager. Revoke any unauthorized permissions via blockchain explorers like Etherscan or via wallet settings. Do not enter seed phrases, private keys, or sign any transactions from this domain. Report the URL to your antivirus provider, wallet platform, and local cybercrime units. Monitor wallets for unauthorized transfers using block explorers. Use hardware wallets or isolated browser profiles for crypto activities and avoid clicking links from unsolicited messages. ## Threat Details - Verdict: SUSPICIOUS - Site status: unknown (HTTP ?) ## Domain Intelligence - Registrar: REGISTRAR_NOT_FOUND - IP: 185.246.190.216 ## Detection Status - VirusTotal: 0 vendors flagged - Google Safe Browsing: clean - Blocklists: 0 hits ## Evidence - Cloudflare Radar: https://radar.cloudflare.com/domains/f.gettrustpayment.live - PhishDestroy: https://phishdestroy.io/domain/f.gettrustpayment.live/ - LLM endpoint: https://phishdestroy.io/domain/f.gettrustpayment.live/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/f.gettrustpayment.live/ Last updated: 2026-04-04