trustwallet-suport.online
“ÐоÑÑи гоÑово! Ðомен ÑÑпеÑно пÑивÑзан к Ñ Ð¾ÑÑингє
Evidence Summary
This domain is flagged for impersonating Trust Wallet, a cryptocurrency wallet service, with the intent to deploy crypto drainer malware. Analysis indicates the site is designed to trick users into entering recovery phrases or private keys, enabling attackers to siphon funds from connected wallets. The domain mimics legitimate Trust Wallet branding, including logos, color schemes, and interface elements, to lower user suspicion and increase the likelihood of successful credential theft or wallet compromise. Infrastructure analysis reveals the domain trustwallet-suport.online was registered on July 10, 2026, through REG.RU LLC, a registrar frequently exploited for malicious activity. As of the latest scan, the domain has 0 detections across 95 security engines on VirusTotal, indicating it remains unflagged by most threat intelligence platforms. The domain resolves to the IP address 31.31.197.50, which has no prior association with legitimate Trust Wallet infrastructure. No blocklist entries or public reports exist for this domain, suggesting it is either newly operational or evading detection through obfuscation techniques. Users who have visited trustwallet-suport.online or entered sensitive information should immediately take corrective action. Disconnect any devices used to access the site from the internet and revoke all active wallet sessions. Transfer remaining funds to a new, secure wallet using a clean device, and generate fresh recovery phrases. Monitor all linked accounts for unauthorized transactions and enable multi-factor authentication where available. Report the incident to the legitimate Trust Wallet support team and consider filing a complaint with relevant cybercrime authorities. Do not interact with the domain further, as it remains active and poses an ongoing threat.
Network Security Intelligence
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Hagezi Threat Feed | trustwallet-suport.online |
malicious | Sinkholed |
| Quad9 DNS | trustwallet-suport.online |
malicious | Sinkholed |
Forensic History & Detection Timeline
-
Domain Status Transition Aug 6, 2026 · 01:06 UTCDomain state transitioned from alive to dead.
Threat Response Pipeline
Public Blocklist Status
Evasion analysis
Cloaking & traffic-distribution check
Stored crawler-versus-browser observations for this host, plus a live fingerprint check for Keitaro-style traffic distribution systems.
- Stored cloaking flag
- Not yet scanned
- Last cloaking scan
Scanner note: dns_error: raw=dns_error; via=local_dns_prefilter
Stored Capture · 3 sources
Domain Intelligence
Technical detailsDNS, SSL SANs, timestamps
ICANN OVERSIGHT
Accreditation and RAA context
Accreditation and RAA context
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
VirusTotal Analysis
Site Performance Analysis
Google PageSpeed Insights — mobile performance audit of trustwallet-suport.online · checked Jul 12, 2026
Lookalike domains
104 stored lookalike domains
Show all (88)
Showing 100 of 104
Evidence & External Reports
PD-20260712-96020F Recipient: abuse@reg.ru Abuse notice text as sent to the provider
Registrar: REG.RU (Russia) Policy Violations: Abuse policy + ICANN contractual obligations; phishing classified as bad-faith use in UDRP; domains may be suspended/removed Applicable Laws: Criminal Code RF Art.159 (fraud), Art.272 (illegal access), Art.273 (malware creation), Art.274.1 (critical infrastructure interference)
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive