trusts-card[.]com
“Phantom Card | Spend Crypto Anywhere”
trusts-card.com — Conteúdo indisponível (HTTP 502). Representação da marca: Phantom; Tipo de golpe: Crypto Scam. Resumo das evidências: VirusTotal 3/94 (Gridinsoft, SOCRadar, URLQuery); URLQuery 1 alert; PhishDestroy score 65/100. Registrador: Hello Internet.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
Analysis of trusts-card.com, registered through Hello Internet Corp on 2026-03-11, shows a typical brand‑impersonation infrastructure targeting the Phantom brand. The domain resolves to IP 104.21.60.143, an address owned by AS13335 Cloudflare, Inc. in the United States, and is served behind Cloudflare’s reverse‑proxy service using HTTP/3. DNS is delegated to ezra.ns.cloudflare.com and jocelyn.ns.cloudflare.com, indicating a standard Cloudflare DNS configuration. The site employed a Node.js stack with Vue.js and Nuxt.js, and included third‑party trackers such as Facebook Pixel and Cloudflare Browser Insights, confirming the presence of modern web technologies but providing no indication of malicious code.
A Let’s Encrypt E8 certificate secured the site, which is typical for short‑lived malicious domains. VirusTotal records show three of ninety‑four scanning engines flag the domain, and PhishDestroy has already added it to its blocklist; it also appears on one additional security blocklist. The page title “Phantom Card | Spend Crypto Anywhere” directly references the targeted brand, confirming the impersonation intent.
The site is currently offline, so active payload delivery cannot be verified. Defenders should continue to block the domain at DNS and proxy layers, monitor for any re‑hosting attempts on alternative IP ranges, and educate users that any unsolicited request to acquire a “Phantom Card” for cryptocurrency spending is likely fraudulent. Ongoing vigilance is advised, especially given the elevated risk rating and the observed use of reputable cloud services to obscure the attacker’s origin.
Inteligência de segurança de rede
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| YARAhub by abuse.ch | trusts-card.com/ |
malware | Detects file containing Telegram Bot API |
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Captura armazenada
Inteligência de Domínios
Detalhes técnicosDNS, SANs do SSL, carimbos de data e hora
ICANN OVERSIGHT
Credenciamento e contexto RAA
Credenciamento e contexto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Tecnologias · 7 identified
JavaScript runtime built on Chrome V8 engine for server-side development.
Progressive JavaScript framework for building user interfaces.
Hybrid Vue framework for server-side rendering and static sites.
Conversion-tracking pixel by Meta — logs page views and custom events to Facebook/Instagram ad accounts.
www.facebook.comPerformance monitoring tool that measures website speed from real users.
www.cloudflare.comWeb infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Análise do VirusTotal
Evidências arquivadas
Análise de desempenho do site
Google PageSpeed Insights — mobile performance audit of trusts-card.com · checked Mar 11, 2026
Evidências e relatórios externos
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo