MALICIOUS — CRITICAL
d[.]gettrustpayment[.]live
PhishDestroy identifies gettrustpayment.live as a live payment-themed phishing domain designed to steal financial credentials and personal information from unsuspecting users.
- VirusTotal
- 17/94
- Blocklists
- 1 · ScamSniffer
- 가용성
- 콘텐츠를 사용할 수 없음 · HTTP 502
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
d.gettrustpayment.live — 콘텐츠를 사용할 수 없음 (HTTP 502). 브랜드 사칭: Trust Wallet; 사기 유형: Brand Impersonation. 증거 요약: VirusTotal 17/94 (ADMINUSLabs, alphaMountain.ai, BitDefender, CRDF, Emsisoft); URLQuery 1 alert; URLScan malicious verdict; Spamhaus DBL_PHISH; 1 external blocklist match (ScamSniffer); PhishDestroy score 95/100.
원본 포렌식 기록을 보존하기 위해 아래의 상세 PhishDestroy AI 분석은 영어로 유지됩니다.
Evidence Analysis
PhishDestroy identifies gettrustpayment.live as a live payment-themed phishing domain designed to steal financial credentials and personal information from unsuspecting users. This fraudulent site masquerades as a legitimate payment verification page, tricking visitors into entering sensitive card details or login credentials under the false pretense of resolving a payment issue. The domain leverages urgency-based social engineering, such as fake transaction alerts or account suspension warnings, to pressure users into submitting data without scrutiny. While currently undetected by most antivirus engines, its active status and deceptive branding make it a serious threat to online shoppers and banking customers. This domain was flagged by PhishDestroy using seed bfa3e2, with zero detections across 95 VirusTotal engines as of the latest scan. Registered through an anonymous registrar, the site operates under Let's Encrypt SSL certificate (valid for phishing purposes) resolving to IP address 185.246.190.216, hosted in a high-risk network segment. The domain is newly active, indicating a rapidly deployed campaign likely targeting recent events such as seasonal sales or tax deadlines to maximize victim engagement. Its lack of detection reflects either stealth tactics or a newly launched operation. If you visited gettrustpayment.live, immediately stop entering any personal or financial information. Do not click any links or download files from the site. Disconnect from the internet if possible and run a full antivirus scan. Change passwords for any accounts you may have entered, especially banking or email credentials. Report the domain to your bank and local cybercrime unit. Monitor your financial statements for unauthorized transactions. Share this warning with others to prevent further victimization. Avoid reaccessing the domain—it remains active and dangerous.
데이터 적용 범위12 recorded checks
네트워크 보안 인텔리전스
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| YARAhub by abuse.ch | d.gettrustpayment.live/scripts/main.js |
malware | Detects file containing Telegram Bot API |
위협 대응 Pipeline
공개 차단 목록 상태
VirusTotal 분석
사이트 성능 분석
Google PageSpeed Insights — mobile performance audit of d.gettrustpayment.live · checked Apr 4, 2026
증거 및 외부 보고서Independent lookups and source reports
PD-20260404-EE3D8A Recipient: abuse@flokinet.is Victim safety and official reportingImmediate actions and verified reporting channels
계정 자격 증명, 개인 정보 또는 결제 정보를 입력했거나 이 도메인에서 파일을 다운로드한 경우 즉시 조치를 취하세요. 다음은 사건을 신고하고 자신을 보호하는 데 도움이 되는 리소스입니다.
지역 당국에 신고하십시오
공식 사이버 범죄 연락처 또는 불만사항 초안 작성 →를 받으려면 국가를 선택하세요.