# PhishDestroy threat dossier — trustwallet-helpdesk.org ================================================================ Fetched: 2026-05-17 06:39:29 UTC Canonical: https://phishdestroy.io/domain/trustwallet-helpdesk.org/ ## VERDICT ---------------------------------------------------------------- TAKEN DOWN (neutralised) Composite threat score: 95/100 (PhishDestroy scoring — see methodology below) Scam classification: Impersonation Targeted brand: Trust Wallet ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 0/92 security vendors flagged this domain URLQuery: 2 detections Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 198.251.89.84 (LU, Luxembourg) ASN: AS53667 FranTech Solutions Hosting org: FranTech Solutions Registrar: Dynadot Inc Nameservers: ["cloud1.listedhosting.net", "cloud2.listedhosting.net"] Registered: 2026-05-16 HTTP response: 200 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / R13 Expires: 2026-08-13 Status: INVALID chain Fingerprint: e18ae1385f38933ca72b6e25f5a5e59609ce405c3ea14b48a03daf8bc12e328e ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: CLOSED — no report required. This domain was neutralised before the abuse-report cycle could be dispatched — either the hosting provider / registrar suspended it on their own, the DNS went dead, or the operator abandoned the infrastructure. PhishDestroy keeps the evidence bundle on file for audit but no formal notice was sent. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-05-16 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-05-16 21:17:18 UTC (by PhishDestroy tracker) Earliest abuse rec: 2026-05-16 18:18:41 UTC — PREDATES current WHOIS registration; retained from a previous registration cycle of the same domain name Last verified: 2026-05-17 08:40:16 UTC Neutralised: 2026-05-17 00:50:15 UTC Current status: taken down (registrar suspended or DNS dead) Note: one or more events above predate the WHOIS creation date. This typically means the same domain name was previously registered, detected, dropped, and then re-registered by a new party. PhishDestroy preserves the full historical record for operator-attribution research even when the underlying infrastructure changes hands. ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019e31ff-43ff-740d-8e22-73abd60f2092/ URLQuery: https://urlquery.net/report/9c1c3f82-d85b-4e25-a650-e1bc07c3d79f Wayback Machine: https://web.archive.org/web/*/trustwallet-helpdesk.org crt.sh CT logs: https://crt.sh/?q=%25.trustwallet-helpdesk.org Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=trustwallet-helpdesk.org AlienVault OTX: https://otx.alienvault.com/indicator/domain/trustwallet-helpdesk.org URLhaus: https://urlhaus.abuse.ch/host/trustwallet-helpdesk.org/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-05-16 21:19:07 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] PhishDestroy identifies trustwallet-helpdesk.org as an active brand-impersonation site posing as Trust Wallet’s official support desk. This fake domain is engineered to steal cryptocurrency by luring users into entering wallet recovery phrases or connecting drained wallets under the guise of “help desk” assistance. By mimicking a support interface, it exploits trust and urgency, a common tactic among crypto drainers that siphon funds within minutes of credential submission. Users who land here risk irreversible asset loss, as any connected wallet or entered seed phrase can be drained instantly by the operators behind this infrastructure. This domain was flagged within hours of creation on May 14, 2026, through automated detection pipelines that monitor for impersonation of major crypto brands. Despite only 0 detections on VirusTotal as of analysis time, further investigation reveals a Let’s Encrypt SSL certificate, a unique seed identifier of 6d2a04, and a single blocklist inclusion. The site operates from IP 198.251.89.84, hosted via a Dynadot LLC registrar—an entity frequently associated with disposable domains used in low-volume but high-impact phishing campaigns. The absence of antivirus coverage highlights the evolving nature of these threats, which often evade signature-based detection until post-infection forensics or community reporting surfaces them. If you visited trustwallet-helpdesk.org or entered any details, act immediately: disconnect your device from the internet, revoke any wallet connections or permissions via your wallet’s official interface (not via email links), and transfer remaining assets to a new, isolated wallet. Do not trust pop-ups or redirected support chat windows claiming to “secure” your funds—these can be part of the same attack chain. Report the domain to PhishDestroy using the unique seed 6d2a04 for collective threat intelligence enrichment. Always verify support channels directly from the official Trust Wallet website or verified apps, never through third-party search results or unsolicited messages. ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260516-74DE5F TLS cert SHA-256: e18ae1385f38933ca72b6e25f5a5e59609ce405c3ea14b48a03daf8bc12e328e ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (volunteer takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/trustwallet-helpdesk.org/ JSON API: https://api.destroy.tools/v1/check?domain=trustwallet-helpdesk.org Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: volunteer-driven open-source threat-intelligence platform. Tracked: 150,558 domains (27,887 alive under monitoring, 122,391 confirmed takedowns/dead). Site: https://phishdestroy.io