# PhishDestroy threat dossier — trustwellfinancialbank.world ================================================================ Fetched: 2026-07-27 15:52:43 UTC Canonical: https://phishdestroy.io/domain/trustwellfinancialbank.world/ ## VERDICT ---------------------------------------------------------------- CRITICAL THREAT — DO NOT VISIT Composite threat score: 100/100 (PhishDestroy scoring — see methodology below) Scam classification: Impersonation Targeted brand: Trust Wallet ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 1/91 security vendors flagged this domain Flagging vendors: Netcraft AlienVault OTX: 4 pulses (threat-intel feed mentions) Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 162.245.237.212 (US, Tukwila) ASN: AS27323 Wowrack.com Hosting org: CENTRIOHOST-LLC Registrar: OwnRegistrar, Inc. Nameservers: dns1.webproserver.com, dns2.webproserver.com Registered: 2025-11-03 Expires: 2026-11-03 Page title: TrustWell financial Bank HTTP response: 200 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / YR1 Expires: 2026-08-27 Status: INVALID chain Fingerprint: 4026994c50cf7ecde04e1d92ca8c509240e893bb2d0c0db18c2d78c23d3e0d6a ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2025-11-03 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-07-27 09:36:15 UTC (by PhishDestroy tracker) First reported: 2026-07-27 13:17:58 UTC (abuse notice filed) Last verified: 2026-07-27 16:20:20 UTC Current status: ACTIVE / observable ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019fa2e1-fe79-737f-a7ae-b25810bd7e13/ URLQuery: https://urlquery.net/report/49a9a1ad-3d17-46c9-8b73-15aee8e2d978 Wayback Machine: https://web.archive.org/web/*/trustwellfinancialbank.world crt.sh CT logs: https://crt.sh/?q=%25.trustwellfinancialbank.world Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=trustwellfinancialbank.world AlienVault OTX: https://otx.alienvault.com/indicator/domain/trustwellfinancialbank.world URLhaus: https://urlhaus.abuse.ch/host/trustwellfinancialbank.world/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-27 09:39:39 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] trustwellfinancialbank.world — Banking Phishing Report The domain trustwellfinancialbank.world is currently active and has been identified as a banking phishing infrastructure. Registration data shows the domain was created on November 03, 2025 through OwnRegistrar, Inc., and it is served by the authoritative name servers dns1.webproserver.com and dns2.webproserver.com. DNS resolution points to a single IPv4 address, 162.245.237.212, which is the sole hosting endpoint observed for this indicator. The domain appears on one external blocklist; PhishDestroy has listed it as malicious, providing an additional confirmation of its abusive nature. VirusTotal analysis indicates that one out of ninety‑one security vendors submitted a detection for the domain, suggesting that at least one scanning engine has recognized it as suspicious, while the majority of engines have not yet flagged it. No public information is available regarding SSL certificates, HTTP response codes, page titles, or other web‑layer artifacts, and no further intelligence such as OTX tags or additional blocklist entries has been reported. The limited visibility of the hosting environment and the sparse detection footprint mean that the full scope of the campaign—such as victim targeting, credential harvesting methods, or command‑and‑control pathways—remains uncertain. Defenders should immediately add trustwellfinancialbank.world to network deny lists and endpoint URL filtering rules, monitor DNS queries for the associated name servers and IP address, and consider sinkholing the IP if feasible. Continuous re‑scanning with multi‑vendor services is advised to capture any future changes in detection status, and threat‑intel teams should track any new sightings that might reveal additional infrastructure or payload details. ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260727-2E998D Favicon MD5: bb9cc0b39bfd7a6f09d0dff130c52823 TLS cert SHA-256: 4026994c50cf7ecde04e1d92ca8c509240e893bb2d0c0db18c2d78c23d3e0d6a ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/trustwellfinancialbank.world/ JSON API: https://api.destroy.tools/v1/check?domain=trustwellfinancialbank.world Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 205,914 domains (81,086 alive under monitoring, 123,797 confirmed takedowns/dead). Site: https://phishdestroy.io