trustwalletdownload[.]co[.]com
Riepilogo delle prove
Analysis of trustwalletdownload.co.com indicates that the domain is being used to impersonate the Trust Wallet brand in a crypto‑related scam. The site is currently offline, but historical data shows it resolved to the IP address 169.60.151.233, which is hosted by SoftLayer Technologies, Inc. in the United States. The domain was registered on August 16, 1997 through Moniker Online Services LLC and is served by the four authoritative name servers ns1.nic.co.com through ns4.nic.co.com. No SSL certificate was observed for the host, meaning traffic would have been delivered over plain HTTP. Infrastructure scoring from Gridinsoft assigns the domain a trust score of 0 out of 100, reflecting a high likelihood of malicious intent.
The domain appears on a single security blocklist and has been flagged by the PhishDestroy blocklist, confirming that defensive feeds have recognized it as a threat. VirusTotal reports that the domain was scanned by 95 vendors, none of which raised a detection; however, the absence of detections does not constitute evidence of safety, especially given the other corroborating indicators. The brand target is explicitly listed as Trust Wallet, and the scam type is identified as a crypto scam, suggesting that any future payloads would aim to harvest cryptocurrency credentials or funds. Because the site is offline, direct observation of its content is not possible, leaving the exact phishing page layout and lure techniques unknown.
Defenders should continue to block the domain at perimeter and DNS layers, monitor for any re‑activation of the host, and add the IP address 169.60.151.233 to threat‑intel feeds. Additional scrutiny of any traffic originating from SoftLayer’s network for similar brand‑impersonation patterns is recommended. Organizations using Trust Wallet should educate users about the risk of unsolicited download links and enforce strict URL verification policies.
Data Coverage
Pipeline di risposta alle minacce
Copertura delle blocklist
10 fonti esterne monitorate · snapshot del 13/08/2026
10 fonti esterne monitorate Nessuna corrispondenza
Cronologia del rilevamento
-
Stato del dominio
Raggiungibile → Non raggiungibile
-
Cloudflare Radar
Scansione Cloudflare Radar archiviata · Apri scansione
-
Stato del dominio
Non raggiungibile → Raggiungibile
Analisi dei domini
Dettagli tecniciDNS, nomi TLS e date
Analisi di VirusTotal
Questo sito ti ha influenzato in qualche modo?
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.
Verifica qualsiasi dominio
Analisi delle minacce utilizzando blocklist archiviate, WHOIS, DNS e prove di scansione pubblica
Scansiona oraSegnala un tentativo di phishing
Segnala i domini sospetti al nostro database delle minacce — proteggi la comunità
SegnalaFeed in tempo reale sulle minacce
Segnalazioni recenti di phishing e modifiche osservate della disponibilità
MonitoraRimani informato, rimani al sicuro
Controlla le minacce in tempo reale oppure contesta questa segnalazione se ritieni che si tratti di un falso positivo