secure[.]inc-trust-wallet-locked[.]es
“www.bing.com”
secure.inc-trust-wallet-locked.es — Encoberto · alcançável. Representação da marca: Trust Wallet; Tipo de golpe: Crypto Scam. Resumo das evidências: VirusTotal 6/91 (ADMINUSLabs, Chong Lua Dao, CRDF, CyRadar, Fortinet); Spamhaus DBL_PHISH; 2 external blocklist matches (MetaMask, SEAL); cloaking observed; PhishDestroy score 68/100.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
The domain secure.inc-trust-wallet-locked.es was registered on 21 February 2026 and remains active as of 12 July 2026. It is flagged under the threat type “brand_impersonation” targeting the Trust Wallet brand. The domain resolves to the IPv4 address 104.21.41.180, which is hosted by Cloudflare, Inc. in Canada. The site currently returns an HTTP 403 response, and the page title reported by scanners is “www.bing.com”, a mismatch that suggests intentional obfuscation.
Automated reputation services assign a Gridinsoft trust score of 0 out of 100, indicating a completely untrusted classification. The SSL certificate presented is identified only as “WE1”, without further validation details, which is typical of rapidly deployed malicious infrastructure. The domain appears on a single security blocklist and has been actively blocked by the PhishDestroy service, confirming that it is recognized by at least one mitigation platform.
Analysis indicates the domain is being used to impersonate Trust Wallet, a popular cryptocurrency wallet application, and is categorized as a cryptocurrency‑related scam. No additional content has been captured beyond the page title, so the exact payload or credential‑harvesting mechanism remains unknown. The presence of a Cloudflare front‑end suggests the operators are leveraging the provider’s CDN and protection services to hide the true origin of any malicious payloads.
Defenders should add 104.21.41.180 and secure.inc-trust-wallet-locked.es to deny‑list rules on perimeter and endpoint filters, and monitor DNS queries for the domain. Continuous re‑inspection of the URL is advised to detect any change in HTTP status or content that could reveal phishing forms or malicious scripts. Coordination with threat‑intel sharing feeds is recommended to track any emergence of additional indicators of compromise linked to this infrastructure.
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Análise do VirusTotal
Evidências e relatórios externos
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo