Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is compliance_abuse@webnic.cc.
The latest stored availability evidence still shows the domain reachable; 3 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
trust-wallet[.]coupons
“Receive USDT”
trust-wallet.coupons — No verificado. Suplantación de marca: Trust Wallet; Tipo de estafa: Brand Impersonation. Resumen de las pruebas: VirusTotal 7/91 (ChainPatrol, alphaMountain.ai, Chong Lua Dao, CRDF, Fortinet); URLQuery 3 alerts; Spamhaus DBL_PHISH; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 85/100. Registrador: Web Commerce Communica….
El análisis detallado de PhishDestroy AI se mantiene en inglés para conservar el registro forense original.
The domain trust-wallet.coupons was registered on 28 April 2026 through Web Commerce Communications Limited dba WebNic.cc. It is currently reachable over HTTPS using a Google Trust Services certificate (WE1) and resolves to the Cloudflare edge IP 104.21.64.54, which is geolocated to Canada. The site returns HTTP 200 and serves the page title “Receive USDT”, directly mimicking the Trust Wallet brand.
Infrastructure analysis shows the web server runs Node.js with the Express framework, and loads assets from cdnjs. Cloudflare services are evident, including Browser Insights and HTTP/3 support, confirming the use of Cloudflare’s CDN and security stack. The authoritative nameservers are adel.ns.cloudflare.com and lynn.ns.cloudflare.com, reinforcing that the attacker relies on Cloudflare’s DNS and proxy.
Risk assessment classifies the site as a high‑severity brand‑impersonation campaign. The page advertises “Receive USDT”, a common lure to obtain cryptocurrency deposits from unsuspecting Trust Wallet users. Independent scans flag the domain on three security blocklists, and five of ninety‑five VirusTotal scanners label it malicious. It is also listed by PhishDestroy, MetaMask, and SEAL, indicating rapid detection by multiple anti‑phishing feeds.
Defenders should immediately block trust-wallet.coupons at the DNS or proxy layer and add the IP 104.21.64.54 to any network‑level deny lists. Continuous monitoring of Cloudflare‑originated IP ranges for similar impersonation patterns is advised. Because the underlying infrastructure is shared, sinkholing the domain may not be feasible, but threat‑intel feeds should be updated to include this indicator and any future subdomains that resolve to the same nameservers. Organizations that support Trust Wallet users should educate end‑users to verify URLs and discourage the entry of private keys on any site that does not belong to the official trustwallet.com domain.
Inteligencia de seguridad de red
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Nextron YARA rules | trust-wallet.coupons/assets/index-dampzg15.js |
malware | Unique code from Jetriz, Swid & Jeniva of the Tetris framework |
| Nextron YARA rules | trust-wallet.coupons/assets/index-c0rotoaf.js |
malware | Unique code from Jetriz, Swid & Jeniva of the Tetris framework |
| Quad9 DNS | trust-wallet.coupons |
malicious | Sinkholed |
Proceso de respuesta ante amenazas Pipeline
Estado de la lista de bloqueados pública
Captura guardada
Inteligencia de dominios
Detalles técnicosDNS, SAN de SSL, marcas de tiempo
ICANN OVERSIGHT
Acreditación y contexto RAA
Acreditación y contexto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Tecnologías · 6 identified
Node.js is an open-source, cross-platform, JavaScript runtime environment that executes JavaScript code outside a web browser.
nodejs.org 100 % de confianzaExpress is a web application framework for Node.js, released as free and open-source software under the MIT License. It is designed for building web applications and APIs.
expressjs.com 100 % de confianzaCloudflare Browser Insights is a tool that measures the performance of websites from the perspective of users.
www.cloudflare.com 100 % de confianzaCloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100 % de confianzaHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100 % de confianzaAnálisis de VirusTotal
Análisis del rendimiento del sitio
Google PageSpeed Insights — mobile performance audit of trust-wallet.coupons · checked Apr 28, 2026
Datos y informes externos
PD-20260428-8C798D Recipient: compliance_abuse@webnic.cc ¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.