Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is abuse-contact@publicdomainregistry.com.
The latest stored availability evidence still shows the domain reachable; 6 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
trustcard[.]cc
“Trust | Your Private Crypto Card”
trustcard.cc — Não verificado. Representação da marca: Mastercard; Tipo de golpe: Wallet/seed Phishing. Resumo das evidências: VirusTotal 13/91 (alphaMountain.ai, BitDefender, CRDF, CyRadar, ESET); URLQuery 100 det.; URLScan malicious verdict; 1 external blocklist match (ScamSniffer); PhishDestroy score 95/100. Registrador: PDR.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
Analysis of the domain trustcard.cc indicates it was a high-risk phishing infrastructure targeting Mastercard users, specifically designed to impersonate a crypto card service. The domain was registered on February 21, 2026, through PDR Ltd. d/b/a PublicDomainRegistry.com and resolved to the IP address 104.21.66.19, hosted on Cloudflare's network (AS13335) in the United States. Nameservers kristin.ns.cloudflare.com and otto.ns.cloudflare.com were associated with the domain, which lacked an SSL certificate, increasing the risk of unencrypted data interception. The page title, 'Trust | Your Private Crypto Card,' aligns with the reported scam type of wallet or seed phishing, suggesting an attempt to deceive users into divulging cryptocurrency wallet credentials or recovery phrases.
Detection by multiple security vendors and blocklists further supports its classification as malicious. As of July 23, 2026, the domain is offline, but it was previously flagged by four security blocklists (PhishDestroy, MetaMask, ScamSniffer, and SEAL) and appeared in one AlienVault OTX threat intelligence pulse. VirusTotal data shows 15 out of 93 security vendors marked the domain as malicious, though this does not represent a comprehensive verdict. Defenders should treat this domain as confirmed malicious infrastructure.
While it is currently inactive, historical resolution to Cloudflare IPs and the absence of SSL certificates are consistent with phishing campaigns. Organizations should ensure blocklist updates include this domain and monitor for any reactivation or related infrastructure. The registration details and hosting provider do not provide additional attribution, but the timing and targeting of Mastercard users in a crypto-related scam are notable. No further content analysis is available, so the exact mechanics of the phishing kit remain unconfirmed.
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Análise do VirusTotal
Evidências e relatórios externos
PD-20260122-BA7A79 Recipient: abuse-contact@publicdomainregistry.com Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo