trust-wallet[.]claims
“TWT Token Airdrop: Complete Missions and Get Rewarded”
The domain trust-wallet.claims was observed delivering a wallet‑seed phishing campaign that masquerades as a TrustWallet airdrop. The site presented the page title “TWT Token Airdrop: Complete Missions and Get Rewarded” and employed the publicly available Airdrop Scam phishing kit. Technical analysis shows the domain resolves to the IPv4 address 213.165.61.42, which is allocated to AS207713 (GLOBAL INTERNET SOLUTIONS LLC) in Russia. The authoritative nameservers are a.dnspod.com, b.dnspod.com, and c.dnspod.com, and the registration was performed through the GIR_SER‑NET registrar, linking the infrastructure to ASN 207713.
No TLS certificate is presented; the site served only HTTP, reducing the possibility of encrypted traffic inspection. VirusTotal listed the domain in 12 of 95 security vendor checks, and five independent blocklists have already added the host. Additional defensive feeds—including PhishDestroy, ScamSniffer, Polkadot, Enkrypt, and Codeesura—have flagged the domain as malicious. The service has been taken offline at the time of reporting, and no further HTTP response was captured, limiting visibility into the exact payload delivered beyond the page title.
The evidence confirms a targeted impersonation of the TrustWallet brand, specifically aiming to harvest cryptocurrency wallet seeds under the guise of an airdrop. Defenders should add the domain and its resolved IP address to network‑level denial lists, monitor DNS queries for the associated dnspod.com nameservers, and ensure endpoint protection retains the 12 vendor detections for future correlation. Continuous observation of ASN 207713 activity is advised, as related infrastructure may be reused in subsequent campaigns.
Threat Response Pipeline
Public Blocklist Status
Stored Capture
Domain Intelligence
Technical detailsDNS, SSL SANs, timestamps
ICANN OVERSIGHT
Accreditation and RAA context
Accreditation and RAA context
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
VirusTotal Analysis
Evidence & External Reports
“Phishing website!”
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive