trustwalletpay[.]app
“Trust Payment Voucher”
On July 23, 2026 analysts examined the domain trustwalletpay.app, which was created on February 21, 2026 and is registered through NiceNIC International Group Co., Limited. The site resolves to the IP address 172.67.190.7, which belongs to AS13335 Cloudflare, Inc. in the United States. DNS resolution is provided by the Cloudflare nameservers dayana.ns.cloudflare.com and rob.ns.cloudflare.com, indicating that the infrastructure is fully proxied behind Cloudflare’s edge network. No TLS certificate was presented during the scan, meaning the site operated without HTTPS encryption despite Cloudflare’s typical support for automatic TLS.
The page title returned by the server is "Trust Payment Voucher," which aligns with the declared scam type of a crypto scam and the brand target of Trust Wallet. Google Safe Browsing classifies the domain as a social engineering threat, and four independent blocklists (PhishDestroy, Polkadot, Enkrypt, Codeesura) have already listed the domain as malicious. VirusTotal analysis shows that 14 of 95 scanned security vendors flagged the domain, reinforcing the malicious assessment. Detected technologies include Tailwind CSS, HSTS, Cloudflare Browser Insights, and HTTP/3, all of which are typical of legitimate Cloudflare‑hosted sites but do not mitigate the impersonation risk.
The site is currently offline, which may be the result of takedown actions or hosting changes; however, the historical evidence confirms a high‑risk brand‑impersonation campaign. Uncertainty remains around the exact payload or credential‑capture mechanisms, as no page content beyond the title was captured. Defenders should continue to block trustwalletpay.app at perimeter firewalls, update URL filtering policies, and monitor for any re‑hosting attempts using the same registrar or Cloudflare infrastructure. Threat‑intel teams should also correlate any observed traffic to the IP 172.67.190.
Instantané des preuves transmises
- Envoyé
- Entrées du registre
- 1
- ID du dossier
PD-20260211-940470- Titre de la page capturée
- Trust Payment Voucher
- Artefact PDF
- Preuve PDF
Texte intégral des preuves
Policy Violations: “Services may be used only for lawful purposes… fraud, abuse and illegal activity prohibited. Violations may result in immediate suspension.” + dedicated abuse handling and takedown
Applicable Laws: Crimes Ordinance Cap.200 (Fraud), Theft Ordinance Cap.210 §16A (fraud by deception), Personal Data (Privacy) Ordinance Cap.486
Renseignements sur la sécurité réseau Registrar context
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Hagezi Threat Feed | trustwalletpay.app |
malicious | Sinkholed |
Processus de réponse aux menaces Pipeline
Couverture des listes de blocage
10 sources · synchronisées le 10/08/2026
Chronologie de détection
-
stage4.timeline.status
stage4.timeline.transition
-
Cloudflare Radar
stage4.timeline.scan_saved · stage4.timeline.open_scan
-
Cloudflare Radar
stage4.timeline.scan_saved · stage4.timeline.open_scan
Capture enregistrée
Informations sur les domaines
Détails techniquesDNS, noms TLS et horodatages
ICANN OVERSIGHT
Contexte de l’accréditation et du RAA
Contexte de l’accréditation et du RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Analyse VirusTotal
Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif