Skip to security report
⚠️
This domain has been flagged as malicious
Security engines reporting a detection: 3. Exercise extreme caution — do not enter credentials or personal information.
Domain security and threat intelligence

tw-premium[.]io

Threat verdict Critical 71/100 evidence score
Availability Server error The latest stored response was inconclusive
VirusTotal detections: 3/91 Spamhaus DBL: DBL_PHISH Scam type: Crypto Drainer
Jun 15, 2026

Evidence Summary

CRITICAL
Evidence score
71/100

PhishDestroy identifies tw-premium.io as a generic_phishing domain, specifically a credential theft site, which is currently active and poses an elevated risk to users. This domain was flagged for its malicious activity, with a notable brand impersonation attempt, and its status as an active threat is a cause for concern. The domain's impersonation tactics are designed to deceive users into divulging sensitive information, making it a significant threat to online security.

The domain tw-premium.io was created on May 27, 2026, and has been flagged by 3 of 95 VirusTotal vendors, indicating a significant level of malicious activity. Although the registrar name and IP address are not publicly available, the fact that it appears on 1 security blocklist suggests that its reputation is already being questioned by the cybersecurity community. With a relatively recent creation date and a low trust score, this domain's intentions are highly suspect, and its presence on a blocklist further reinforces the need for caution when interacting with it.

Given the current status of tw-premium.io as an active and elevated threat, users are advised to exercise extreme caution when encountering this domain. To protect themselves from potential credential theft, users should avoid interacting with the domain altogether, and instead, report any suspicious activity to the relevant authorities. By taking proactive measures, such as verifying the authenticity of websites and being cautious of unsolicited emails or messages, users can significantly reduce the risk of falling victim to this type of threat, and PhishDestroy recommends that users prioritize their online security to prevent any potential harm from this malicious domain.

VirusTotal
VirusTotal
3 det.
Age
3 mo New
Observed status
Server error HTTP 502
PhishDestroy
DestroyList
Listed

Data Coverage

VirusTotal 3 / 91 URLQuery not checked PhishStats not checked OTX no community references CF Radar scan completed URLScan capture not submitted URLScan verdict verdict unavailable DNS blocks not checked TLS no certificate data WHOIS 3 mo old Screenshot not captured Redirect chain not probed

Threat Response Pipeline

Discovery
Checks
Reports
Availability
6/8

Blocklist coverage

10 monitored external feeds · stored snapshot Aug 12, 2026

10 monitored external feeds No match

Detection timeline

  1. Cloudflare Radar

    Cloudflare Radar scan stored · Open scan

Domain Intelligence

Domain
Server / ASN AS394695 PDR
IP Reputation IP abuse confidence 0/100 0 reports checked Jul 27, 2026
IP Address 216.10.243.62 IN
GeoIN Mumbai, IN
NetworkAS394695 · P.D.R Solutions FZC
RegistrationCreated May 27, 2026 (76d · New)
HTTP Status502 Error
Elapsed Since First Report 34 days
What we count Raw elapsed time since the first stored abuse report. It is not a registrar response-time measurement. Latest observed status: Server error.
What each report contains Stored outgoing-report records may reference evidence available at the time, such as vendor verdicts, registration data, hosting details, classifications, or screenshots. This page does not infer the exact payload delivered, receipt, acknowledgement, or action by a recipient.
Technical detailsDNS, TLS names and timestamps
First DetectedJun 15, 2026
TLS observationscanned Aug 12, 2026

Technologies

2 high-confidence technologies identified

Cloudflare HTTP/3
Cloudflare Radar
Report This Domain Submit evidence & help protect others

VirusTotal Analysis

3 / 91 security vendors flagged this domain
View on VT
Last analyzed
Forcepoint ThreatSeeker
Fortinet
Gridinsoft

Were You Affected by This Site?

If credentials were compromised, report immediately. Do not engage with recovery scammers.

If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.

Europol
Find the official reporting channel for your EU country
National police directory
Beware of recovery scammers! Recovery scammers may pose as investigators, lawyers, or tracing services. Do not pay upfront fees or disclose credentials. Learn more about recovery fraud →

Report to Your Local Authorities

Select your country to get official cybercrime contacts, or create a complaint draft →.

97-country directory
Template-based draft • optional AI wording assistance requires separate consent Review and submit it yourself

Check Any Domain

Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence

Scan Now

Report Phishing

Submit suspicious domains to our threat database — protect the community

Report

Live Threat Feed

Recent phishing reports and observed availability changes

Monitor

Stay Informed, Stay Safe

Monitor live threats or contest this listing if you believe it's a false positive

Live Threat Feed Appeal This Listing

External tools

HTML · IFRAME

Embed This Report

Share this threat intelligence on your website or blog

embed.html
<iframe
  src="https://phishdestroy.io/embed/domain/tw-premium.io"
  title="PhishDestroy threat report for tw-premium.io"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>