VirusTotal
3 / 94
“TrixWallet — TRON Blockchain Wallet”
3 / 94
checked — no detections recorded
Reportchecked — no match recorded
no community references
Reportprovider verdict: suspicious
Reportstored report
Report Analysis completed
Report11 checked — no blocks
Checked; no threat flag recorded
ReportPhishDestroy identifies web3-trust.digital as an active crypto wallet phishing domain currently under investigation. The threat type is generic_phishing, targeting users with deceptive Web3-related lures to steal cryptocurrency wallet credentials or funds. The domain resolves to IP address 5.149.248.229 using a Let's Encrypt SSL certificate, which may be used to lend false legitimacy to phishing pages. At this time, VirusTotal shows 0 detections out of 95 scanners, indicating low detection coverage despite active phishing behavior.
This domain was flagged with seed 9dd205 and is currently active. Intelligence indicates it has no confirmed presence on major blocklists or domain reputation engines as of the latest scan. The domain uses a free Let's Encrypt certificate, commonly leveraged in phishing campaigns to avoid immediate browser warnings. The associated IP 5.149.248.229 has not been widely flagged, increasing the risk of delayed detection by automated systems. No registrar data or creation date was provided in the seed intelligence, limiting historical context for reputation analysis.
To mitigate risk, users should avoid interacting with web3-trust.digital or any site prompting for crypto wallet access, seed phrase entry, or private key disclosure. Always verify URLs manually and use hardware wallets or trusted interfaces for transactions. Security teams should monitor IP 5.149.248.229 and associated domains for newly emerging phishing infrastructure. Report this domain to your security provider or via PhishDestroy’s submission portal using seed 9dd205 to aid in ongoing threat intelligence gathering.
Stored crawler-versus-browser observations for this host, plus a live fingerprint check for Keitaro-style traffic distribution systems.
Scanner note: unavailable: raw=connection_error; http=0; via=http_proxy; error=SOCKSHTTPConnectionPool(host='web3-trust.digital', port=80): Max retries exceeded with url: / (Caused by NewConnectionEr
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
ns-cloud-d4.googledomains.comLocation describes the IP network.
90562a4cde8723622a55fdeeadf179eb6ace82004dffff2cf611e29f5f08737eSaved certificate metadata. Certificate dates without a timezone are shown as stored. Transport encryption does not establish that the site is trustworthy.
Google PageSpeed Insights — mobile performance audit of web3-trust.digital · checked Apr 21, 2026
11 recorded events. These records describe collected evidence, outgoing notifications and publication; they do not confirm a complete investigation or a takedown.
We scan suspicious URLs, inspect public results and send evidence through the appropriate abuse-reporting channels. The dated events above show what is recorded for this domain. The directory below explains the wider workflow.
Capture the rendered page, requests and visible infrastructure.
Compare the available engine results and retain the analysis timestamp.
Check whether Google currently lists the URL as unsafe.
Inspect a public scan and its recorded network and classification data.
Look for indicator references and related community intelligence.
Compare archived captures and preserve historical context.
Look for matching indicators and associated threat records.
Inspect certificate records and related hostnames.
Compare security resolver responses and record observed blocking.
Inspect the public DNS, TLS, HTTP and technology surface.
Security services used for scanning, reputation checks and reporting are listed below. A service being listed is not evidence that it received, accepted or acted on this particular domain. Recorded submissions appear in the notification history above.
Reported by 1 community member, first seen Apr 21, 2026
PD-20260421-F2A502 Recipient: abuse@hostzealot.com Policy Violations: Illegal Activities: Active phishing operation targeting victims Fraud & Deception: Impersonation of legitimate services Identity Theft: Collection of credentials under false pretenses Applicable Laws (Unknown): International Anti-Cybercrime Regulations Budapest Convention on Cybercrime Universal Fraud Prevention Laws Phishing activities violate international cybercrime conventions and Unknown's domestic fraud laws. Action Required: This evidence-backed report demonstrates clear violations requiring suspension per your policies. Continued hosting exposes your organization to regulatory scrutiny and potential legal liability.
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Select your country to get official cybercrime contacts, or create a complaint draft →.
Template-based draft · optional AI wording assistance requires separate consent
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowSubmit suspicious domains to our threat database — protect the community
ReportRecent phishing reports and observed availability changes
MonitorMonitor live threats or contest this listing if you believe it's a false positive