MALICIOUS — CRITICAL
ha138[.]com
The domain ha138.com is identified as a brand impersonation threat specifically targeting Trust Wallet, a cryptocurrency wallet service.
- VirusTotal
- 5/91
- Blocklists
- No stored match
- उपलब्धता
- अंतिम ज्ञात सक्रिय · HTTP 301
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
ha138.com — अंतिम ज्ञात सक्रिय (HTTP 301). ब्रांड प्रतिरूपण: Trust Wallet; घोटाले का प्रकार: Crypto Scam. साक्ष्य सारांश: VirusTotal 5/91 (alphaMountain.ai, CRDF, Gridinsoft, LevelBlue, SOCRadar); PhishDestroy score 80/100. रजिस्ट्रार: NameCheap.
मूल फॉरेंसिक रिकॉर्ड सुरक्षित रखने के लिए नीचे का विस्तृत PhishDestroy AI विश्लेषण अंग्रेज़ी में रखा गया है।
Evidence Analysis
ha138.com Trust Wallet Impersonation Domain – Crypto Scam Warning
ha138.com is a brand impersonation threat targeting Trust Wallet users. Flagged by 4/95 VirusTotal vendors, registered via NameCheap, and linked to crypto.
The domain ha138.com is identified as a brand impersonation threat specifically targeting Trust Wallet, a cryptocurrency wallet service. Analysis confirms this domain was designed to deceive users into believing they are interacting with legitimate Trust Wallet infrastructure, likely to facilitate unauthorized transactions or credential harvesting. The domain is currently offline, though prior activity suggests it operated as part of a broader crypto-draining scheme. Infrastructure analysis reveals ha138.com was registered through NameCheap, Inc. on November 15, 2025, and resolved to the IP address 47.76.197.103. The domain appears on one security blocklist and holds a Gridinsoft trust score of 0 out of 100, indicating high-risk classification. VirusTotal reports that 4 of 95 security vendors flagged this domain as malicious. The page title, 'HX.DUSelflessColorUSDTBlockchainDecentralizedGame,' suggests an attempt to mimic blockchain or decentralized finance (DeFi) terminology to lend credibility to the fraudulent operation. Detected technologies include Vue.js for dynamic content rendering and HTTP Strict Transport Security (HSTS), while the SSL certificate was issued by Let’s Encrypt, a common tactic to evade basic security warnings. The domain’s current offline status does not eliminate the risk, as threat actors frequently reactivate or repurpose infrastructure. Organizations and individuals are advised to block ha138.com and its associated IP (47.76.197.103) at the network level. End users should verify wallet addresses independently before transactions and avoid interacting with unsolicited links or communications claiming to represent Trust Wallet. Security teams should monitor for related domains registered via NameCheap or resolving to the same IP range, as these may indicate follow-up campaigns. Cryptocurrency users are further cautioned to enable multi-factor authentication and review transaction histories for unauthorized activity.
Stored source results
Recorded verdicts and infrastructure observations for this domain.
डेटा कवरेज12 recorded checks
नेटवर्क सुरक्षा इंटेलिजेंस
धमकी प्रतिक्रिया पाइपलाइन
सार्वजनिक ब्लॉकलिस्ट स्थिति
सहेजा गया कैप्चर
डोमेन इंटेलिजेंस
तकनीकी विवरणडीएनएस, एसएसएल एसएएन, टाइमस्टैम्प
ICANN OVERSIGHT
प्रत्यायन और आरएए संदर्भ
प्रत्यायन और आरएए संदर्भ
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
तकनीकें · 2 identified
Progressive JavaScript framework for building user interfaces.
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
वायरसटोटल विश्लेषण
संग्रहीत साक्ष्य
साइट प्रदर्शन विश्लेषण
Google PageSpeed Insights — mobile performance audit of ha138.com · checked Jun 27, 2026
साक्ष्य और बाहरी रिपोर्टेंIndependent lookups and source reports
“I was scammed after purchasing a Nexa calling service through WhatsApp. The seller instructed me to send payment in USDT (TRC20) to the following wallet: TFVz7LWnkJZZ5Db4LTog4VhoJ9Ywgj2FP9 I transferred 901.36 USDT (TRC20). Transaction Hash: 2c71c72b873ececb30d75a1bd4fe89c034ae605430faf41147ff1594f7ac0f51 After I completed the payment, the seller acknowledged receiving the funds and stated that they would ask their finance department to verify the payment. However, after receiving”
Victim safety and official reportingImmediate actions and verified reporting channels
यदि आपने खाता क्रेडेंशियल, व्यक्तिगत या भुगतान जानकारी दर्ज की है, या इस डोमेन से कोई फ़ाइल डाउनलोड की है, तो तुरंत कार्रवाई करें। घटना की रिपोर्ट करने और अपनी सुरक्षा करने में आपकी सहायता के लिए नीचे संसाधन दिए गए हैं।
अपने स्थानीय अधिकारियों को रिपोर्ट करें
आधिकारिक साइबर अपराध संपर्क, या एक शिकायत ड्राफ्ट बनाएं → प्राप्त करने के लिए अपना देश चुनें।