This domain has been flagged as malicious
Detected by 0 of 95 security vendors and listed in 1 public blocklists. Do not connect a wallet; do not paste a seed phrase.

tw-protocol[.]org

Domain Security & Threat Intelligence Report
“Trust - Crypto Card”
0/95 VT Malicious May 17, 2026 1 Blocklist 1 Report Sent Drift
Case PD-20260516-3225D0 Appeal listing
0 Risk Score
Data coverage VirusTotal 0 / 95 URLQuery no det. OTX no pulses CF Radar URLScan report ready DNS blocks none SSL valid, 84d WHOIS Screenshot captured Redirect chain not probed CDN bypass n/a
VirusTotal
no det.
URLQuery
no det.
URLScan
Report ↗
SSL
Let's Encrypt
Age
Status
Live
DestroyList
Listed
Reports Sent
1
02

Forensic brief

auto-generated · PhishDestroy AI
PhishDestroy AI
probe: May 17, 2026
score: 65/100
case: PD-20260516-3225D0
vendors0/95
blocklists1
Analyst brief · auto-generated

PhishDestroy identifies tw-protocol.org as an active brand impersonation scam masquerading as Drift to deceive visitors. This domain leverages visual and textual cues to appear legitimate, aiming to trick users into divulging credentials or downloading malicious payloads under the guise of an official service. The domain was registered solely to impersonate Drift, exposing users to credential theft or crypto drainer attacks if any interaction occurs. Evidence confirms the threat: VirusTotal shows 0 out of 95 security engines flagging the domain, indicating it remains undetected by most antivirus solutions as of the latest scan. The domain was created on May 10, 2026, and is registered through Global Domain Group LLC. It resolves to IP 172.67.199.247 and uses a Let's Encrypt SSL certificate to appear trustworthy. These indicators, combined with the domain's recent creation and impersonation intent, highlight a high-risk threat. If you visited tw-protocol.org, do not enter any credentials or download files. Clear your browser cache and cookies related to the site. Run a full antivirus scan on your device. Report the domain to your IT security team or use a trusted URL checker like VirusTotal to verify its status. Avoid clicking any links or interacting further to prevent potential credential theft or malware installation.

Brand Impersonation Impersonation clean drainer brand: Drift
03

Threat response pipeline

May 17, 2026 · 1 report submitted
Discovery
Submission
Legal
Takedown
9/19
30+ Proprietary Parsers
Distributed scanning of Google Ads, SEO-manipulated results, Twitter/X, YouTube & Telegram campaigns.
Infrastructure Analysis
dnstwist & typosquatting detection against Drift.
Community Intelligence
Real-time ingestion via Telegram Bot & partner intelligence feeds.
Threat Ingested
tw-protocol.org detected and queued for full analysis.
May 17, 2026
48+ Vendor Submissions
Threat data submitted to 48+ security vendors & threat-intel platforms.
Cloudflare Radar
View scan — verdict: pending
Blocklist Detection
Found in 1 blocklists: PhishDestroy.
Forensic Evidence Collection
URLScan.io, URLQuery & Cloudflare Radar — DOM snapshots, HTTP transactions, DNS & certificate data.
Registrar & Hosting Notification
Abuse report sent to Global Domain Group LLC at abuse@globaldomaingroup.com with forensic evidence (metadata, screenshots, PDF).
1778965450
DestroyList Published
Added to PhishDestroy/DestroyList — open-source blocklist for wallets & extensions.
Abuse Reports Sent (1)
1 abuse reports filed; 7h elapsed since first report.
Open Threat Database
Real-time commits to GitHub repository & live monitoring at phishdestroy.io/live.
Social Broadcasting
Automated alerts on X, Telegram & Mastodon.
Awaiting Takedown
Domain still active — monitoring & re-reporting continues. 7h since first report.
04

Evidence capture

urlscan snapshot · domain intelligence
Live Snapshot
2026-05-17 04:30 UTC
Malicious · 0/95 engines
Forensic screenshot of tw-protocol.org
IP: 172.67.199.247
Global Domain Group LLC
Let's Encrypt
Page Title
Trust - Crypto Card
Favicon Hash
58fd2a12f571cafad976ed5feddeeacc

Domain Intelligence

Domaintw-protocol.org
Registrar Global Domain Group LLC(US)
IP Address 172.67.199.247
ASN 13335 · Cloudflare, Inc.
Registration Created 2026-05-16 22:07:02
SSL Let's Encrypt · valid 84d · expires 2026-08-09
Hosting CA Toronto , CA · Cloudflare, Inc.
Nameservers ["brad.ns.cloudflare.com"
Impersonates Drift · Impersonation
Page title “Trust - Crypto Card”
HTTP status 200 · redirects to tw-protocol.org
Technical details DNS, hashes, case ID
Favicon hash58fd2a12f571cafad976ed5feddeeacc
SSL fingerprintcd0c9a549886b86cb1ca829cfc8a5b36a9347d650fc24df0c1b2a3b42453ac38
Case IDPD-20260516-3225D0
08

Public blocklist status

cross-vendor confirmation
1
Listed in 1 public blocklist — confirmed by independent sources
Sources with no listing are omitted.
10

VirusTotal consensus

95 vendors · 3-col matrix
0/95
vendors flagging
No detections

Aggregated detection across 95 security vendors.

Per-vendor breakdown not available — view raw report on VirusTotal ↗
11

Site performance

PageSpeed Insights · mobile
Site performance analysis

Google PageSpeed Insights — mobile audit of tw-protocol.org

95
Good
Performance
FCP
2.02
First Contentful Paint
LCP
2.44
Largest Contentful Paint
CLS
0
Cumulative Layout Shift
TBT
77
Total Blocking Time
SI
2.72
Speed Index
12

Evidence & external reports

cross-reference this domain
14

Were you affected by this site?

immediate response · authorities

Were You Affected?

You are not alone and there is nothing to be ashamed of. Reporting is the most powerful weapon against fraud — your report can prevent others from becoming victims.
Beware of recovery scammers! No legitimate service will ask for upfront payment to recover stolen crypto. Learn more about recovery fraud →
15

Report to your local authorities

geo-aware · authorities · AI complaint
Your country (auto-detected)
Canada

  Email template — registrar abuse

To: abuse@globaldomaingroup.com Registrar: Global Domain Group LLC Case: PD-PD-20260516-3225D0
Open in mail client Appeal (if false-positive)
16

Embed this report

iframe · sizer · CC-BY

Embed this report

Drop a live, self-updating risk widget anywhere — blog, DAO forum, Discord webhook, X post. Free, no API key, CC-BY.

tw-protocol[.]org 65/100 MALICIOUS · 0/95 VT · 7h View full report ↗
Live preview at 100% width
Canonical: https://phishdestroy.io/domain/tw-protocol.org/ JSON API llm.txt
17

About this report

methodology · appeals · API

About this report: tw-protocol.org

This domain security report is maintained by PhishDestroy's automated threat-intelligence pipeline. Our system continuously monitors this domain across 95 security vendors on VirusTotal and 1 public blocklists.

The site displays a page titled “Trust - Crypto Card”.

tw-protocol.org has been flagged by 0 security vendors as of May 17, 2026.

If you believe this listing is inaccurate, you can submit an appeal. For more information about our methodology, visit our FAQ page.