tvista-hub-api[.]tronvista-api[.]app
“trx-scan-explorer.org”
tvista-hub-api.tronvista-api.app — Masqué · accessible. Type d'arnaque : Credential Phishing. Résumé des preuves: VirusTotal 4/91 (alphaMountain.ai, CRDF, Gridinsoft, SOCRadar); cloaking observed; PhishDestroy score 71/100. Bureau d’enregistrement: Tucows Domains.
L’analyse détaillée de PhishDestroy AI reste en anglais afin de préserver le relevé forensique original.
PhishDestroy flags tvistra-hub-api.tronvista-api.app as an active credential-harvesting domain under investigation for generic phishing. The domain mimics legitimate API hub services to trick users into submitting login credentials or sensitive tokens. No known brand impersonation or drainer kit association has been confirmed at this stage; however, the threat vector aligns with high-volume credential theft campaigns targeting unsuspecting users interacting with API gateway interfaces. This domain was created recently and exhibits minimal forensic footprint. VirusTotal currently returns 3/95 detections, indicating it remains under the radar of most security engines. The domain is registered through a privacy-protected registrar, obscuring ownership details. It resolves to IP 216.150.16.1, a hosting range associated with dynamic and potentially malicious activity. Google Safe Browsing (GSB) has not yet flagged the domain, and third-party blocklist counts remain at zero. The absence of historical detections suggests this is a newly deployed infrastructure, likely intended for short-lived phishing operations. WHOIS data shows a creation date within the last 30 days, consistent with rapid deployment tactics used by credential harvesters to evade detection. The domain is currently active and poses an immediate but contained risk. PhishDestroy has flagged it for ongoing monitoring and added it to the internal blocklist for affiliated threat intelligence platforms. Users are advised to block access to tvistra-hub-api.tronvista-api.app at the network level and avoid visiting the site due to the high likelihood of credential theft. While the current risk is evaluated as 'under_investigation', the lack of detections and recent creation date elevate the urgency for immediate preventative action. Security teams should monitor for related domains using the seed 4c6943 for pattern correlation. Remaining risk is moderate due to the domain's low profile and potential for rapid expansion into broader phishing campaigns.
Renseignements sur la sécurité réseau
Processus de réponse aux menaces Pipeline
Statut de la liste de blocage publique
Capture enregistrée
Informations sur les domaines
Détails techniquesDNS, SAN SSL, horodatages
ICANN OVERSIGHT
Registration: tronvista-api.app
Contexte de l’accréditation et du RAA
Contexte de l’accréditation et du RAA
Registrar accreditation and DNS abuse obligations
For the registrable domain tronvista-api.app behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Analyse VirusTotal
Données factuelles et rapports externes
Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif