# trestwalt.blogspot.com — SUSPICIOUS > PhishDestroy flags trestwalt.blogspot.com as a fake Trust Wallet login page. This crypto drainer already evades 95 scanners. Stop by PhishDestroy to verify now. ## Summary PhishDestroy identifies trestwalt.blogspot.com as a brand-impersonation scam targeting Trust Wallet users. Operating under the guise of a legitimate wallet service, this fraudulent domain employs a fake login portal designed to harvest private keys and drain crypto assets. The page is hosted on Blogger, leveraging Google’s infrastructure to lend false credibility while concealing the true intent behind a thin veneer of legitimacy. Initial behavioral analysis suggests the site may redirect victims to a crypto drainer kit capable of exfiltrating funds upon wallet connection, a tactic commonly observed in modern wallet impersonation campaigns. Technical indicators confirm this domain is a live threat. VirusTotal currently shows 0 detections out of 95 engines, indicating evasion of mainstream scanners. The domain resolves to IP 142.251.110.132 and is protected by a Google Trust Services SSL certificate. Registered via Blogger (Google), the domain has been active for an undisclosed period but is flagged by two independent security blocklists and blocked by MetaMask and SEAL. These attributes—combined with its use of a Google-owned subdomain—highlight the sophisticated blending of trusted infrastructure with malicious intent. As of this report, trestwalt.blogspot.com remains active and under active investigation. Immediate response actions include continued monitoring by PhishDestroy, inclusion in blocklists, and coordination with Google Trust Services for takedown. Despite these efforts, the domain retains a moderate risk profile due to its evasion of detection systems and use of trusted hosting. Users are strongly advised to verify any wallet-related site via PhishDestroy before entering credentials or connecting wallets. Remaining risk includes continued fraudulent activity and potential expansion into broader phishing or malware distribution. ## Threat Details - Verdict: SUSPICIOUS - Site status: unknown (HTTP ?) - Target brand: Trust Wallet ## Domain Intelligence - Registrar: REGISTRAR_NOT_FOUND - IP: 142.251.110.132 ## Detection Status - VirusTotal: 0 vendors flagged - Google Safe Browsing: clean - Blocklists: 2 hits Lists: ["MetaMask", "SEAL"] ## Evidence - Cloudflare Radar: https://radar.cloudflare.com/domains/trestwalt.blogspot.com - PhishDestroy: https://phishdestroy.io/domain/trestwalt.blogspot.com/ - LLM endpoint: https://phishdestroy.io/domain/trestwalt.blogspot.com/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/trestwalt.blogspot.com/ Last updated: 2026-04-10