transfer-tws[.]ink
“Crypto Cards”
transfer-tws.ink — Conteúdo indisponível. Resumo das evidências: VirusTotal 5/91 (ChainPatrol, alphaMountain.ai, Forcepoint ThreatSeeker, Fortinet, SOCRadar); URLQuery 3 alerts; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 85/100.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
Analysis of transfer-tws.ink as of July 23, 2026, indicates this domain is part of active phishing infrastructure targeting financial or trading platforms. The domain resolves to IP address 54.39.106.37 and is currently flagged on at least one security blocklist, including PhishDestroy. While VirusTotal scans from 95 vendors show no detections at the time of this report, this absence does not confirm safety, as phishing domains often evade initial detection. The domain remains operational, returning an HTTP 200 status, suggesting the phishing page is live. Infrastructure details reveal the domain uses Let's Encrypt SSL certificate YR2, a common choice for both legitimate and malicious sites due to its free and automated issuance.
Nameservers are hosted on pdns1.registrar-servers.com and pdns2.registrar-servers.com, a configuration frequently observed in phishing campaigns leveraging bulk domain registration services. No specific brand or kit has been confirmed in the available data, and the exact content of the site has not been analyzed. The domain's naming convention, including 'transfer' and 'tws,' suggests it may impersonate trading, brokerage, or banking services, but this remains unconfirmed without further evidence. Defenders should treat transfer-tws.ink as high-risk until additional analysis confirms its intent.
Network-level blocking is recommended based on the current blocklist presence and active resolution. Organizations should monitor for connections to 54.39.106.37 and investigate any user reports of interaction with the domain. Further investigation is required to determine the targeted brand, phishing kit, or payload. No evidence currently links this domain to advanced persistent threats or nation-state actors.
Inteligência de segurança de rede
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Hagezi Threat Feed | tw-coin.org |
malicious | Sinkholed |
| DNS4EU | tw-coin.org |
malicious | Sinkholed |
| DNS4EU | transfer-tws.ink |
malicious | Sinkholed |
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Tecnologias · 3 identified
Windows Server is a brand name for a group of server operating systems.
microsoft.com 100% de confiançaApplication Request Routing (ARR) is an extension to Internet Information Server (IIS), which enables an IIS server to function as a load balancer.
www.iis.net 100% de confiançaInternet Information Services (IIS) is an extensible web server software created by Microsoft for use with the Windows NT family.
www.iis.net 100% de confiançaAnálise do VirusTotal
Análise de desempenho do site
Google PageSpeed Insights — mobile performance audit of transfer-tws.ink · checked Jul 23, 2026
Evidências e relatórios externos
PD-20260723-740FA8 Recipient: abuse@ovh.ca Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo