The domain trustcarduk.sbs was registered on July 30, 2026 through Hostinger operations, UAB and is currently resolving to the IP address 63.176.8.218. The domain’s authoritative nameservers are dns1.p02.nsone.net through dns4.p02.nsone.net, indicating use of the NSONE DNS platform. Within a day of its creation the domain was flagged by the PhishDestroy blocklist and appears on a single security blocklist, confirming that at least one threat intelligence feed has identified malicious activity associated with it.
VirusTotal records show that the domain has been scanned by 91 vendors; none have raised a detection at the time of this analysis, but the absence of detections does not constitute proof of safety. No public information on SSL certificates, HTTP response codes, page titles, or content has been released, leaving the exact phishing payload and any targeted brand undefined. The rapid creation‑to‑activation timeline, combined with the use of a reputable hosting provider and DNS service, is consistent with a typical credential‑harvesting operation that relies on short‑lived infrastructure to evade long‑term detection.
Defenders should immediately add trustcarduk.sbs to URL filtering and DNS sinkhole policies, block outbound connections to the associated IP 63.176.8.218, and monitor for any related C2 traffic. Continuous re‑scanning of the domain on multi‑vendor platforms is advised, as detection status may change. Analysts should also watch for new domains registered by the same registrar or using the same nameserver set, as threat actors often recycle these components for subsequent campaigns.