MALICIOUS — HIGH
twt-auth.cfd Phishing Intelligence Report - PhishDestroy
twt-auth[.]
The domain twt-auth.cfd hosts a page titled "TrixWallet — TRON Blockchain Wallet" and is classified as an impersonation scam targeting the Blockchain.com brand.
- VirusTotal
- 4/91
- Blocklists
- No stored match
- Ketersediaan
- Belum terverifikasi
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is abuse@digitalocean.com.
The latest stored availability evidence still shows the domain reachable; 1 month has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
Jump to section
twt-auth.cfd — Belum terverifikasi. Peniruan identitas merek: Blockchain.com; Jenis penipuan: Brand Impersonation. Ringkasan bukti: VirusTotal 4/91 (alphaMountain.ai, Fortinet, SOCRadar, Webroot); URLQuery 1 alert; Spamhaus DBL_PHISH; PhishDestroy score 65/100. Registrar: Global Domain Group.
Analisis terperinci PhishDestroy AI di bawah tetap berbahasa Inggris untuk menjaga catatan forensik asli.
Evidence Analysis
The domain twt-auth.cfd hosts a page titled "TrixWallet — TRON Blockchain Wallet" and is classified as an impersonation scam targeting the Blockchain.com brand. This site poses a credential theft threat by mimicking a legitimate cryptocurrency wallet service to deceive users into disclosing sensitive login information or private keys.
Technical evidence confirms the malicious nature of this domain. VirusTotal reports 4 detections out of 95 security vendors. The domain was created on 2026-06-09 and registered through Global Domain Group LLC. It resolves to IP address 138.197.182.119 hosted on AS14061 (DigitalOcean, LLC) located in Germany. The site uses an SSL certificate issued by Let's Encrypt with identifier YE2. Nameservers are ns-cloud-d1.googledomains.com, ns-cloud-d2.googledomains.com, and ns-cloud-d3.googledomains.com. The domain has been flagged by alphaMountain.ai, Fortinet, SOCRadar, and Webroot, and appears on 1 blocklist.
The site is currently offline. Its domain risk score is 61, indicating a high threat level. Users should avoid any interaction with this domain and treat any past exposure as potentially compromised.
Stored source results
Recorded verdicts and infrastructure observations for this domain.
Cakupan data12 recorded checks
Intelijen Keamanan Jaringan
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | twt-auth.cfd |
malicious | Sinkholed |
Alur Tanggapan Ancaman Pipeline
Status Daftar Blokir Publik
Tangkapan tersimpan
Intelijen Domain
Rincian teknisDNS, SAN SSL, cap waktu
ZONA SHORTDOT · BUKTI PUBLIK
.cfd
ShortDot zone evidence
ShortDot zone evidence
The linked repository preserves daily zone observations across seven ShortDot-operated TLDs, including registration volume and abuse-related indicators. This registry context is supporting background and is not an independent detection for the domain in this report.
ICANN OVERSIGHT
Akreditasi dan konteks RAA
Akreditasi dan konteks RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Analisis VirusTotal
Bukti & Laporan EksternalIndependent lookups and source reports
PD-20260619-6AD220 Recipient: abuse@digitalocean.com Victim safety and official reportingImmediate actions and verified reporting channels
Jika Anda memasukkan kredensial akun, informasi pribadi atau pembayaran, atau mengunduh file dari domain ini, segera ambil tindakan. Di bawah ini adalah sumber daya untuk membantu Anda melaporkan insiden tersebut dan melindungi diri Anda sendiri.
Laporkan kepada Pihak Berwenang di Daerah Anda
Pilih negara Anda untuk mendapatkan kontak resmi kejahatan dunia maya, atau membuat draf pengaduan →.