trustwalletcard[.]in
“Trust Wallet - Crypto Card”
trustwalletcard.in — Conteúdo indisponível (HTTP 502). Representação da marca: Ethereum; Tipo de golpe: Crypto Scam. Resumo das evidências: VirusTotal 4/93 (Fortinet, Gridinsoft, SOCRadar, URLQuery); URLQuery 6 alerts; Spamhaus DBL_PHISH; 3 external blocklist matches (MetaMask, ScamSniffer, SEAL); PhishDestroy score 74/100. Registrador: Web Commerce Communica….
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
The domain trustwalletcard.in was registered on February 21, 2026 through Web Commerce Communications Limited and is hosted on Cloudflare infrastructure, resolving to IP address 104.21.56.96 located in the United States under ASN 13335 (Cloudflare, Inc.). The authoritative nameservers are bryce.ns.cloudflare.com and elinore.ns.cloudflare.com. No TLS certificate is presented for the domain, indicating that connections are served without encryption. The site’s page title, "Trust Wallet - Crypto Card," and the listed brand target of Ethereum suggest an attempt to impersonate the Trust Wallet brand and the broader Ethereum ecosystem.
Threat intelligence classifies the activity as a crypto scam, and the domain appears on four independent security blocklists. Multiple anti‑phishing services—including PhishDestroy, MetaMask, ScamSniffer, and SEAL—have identified and blocked the site. VirusTotal analysis reports four positive detections out of ninety‑three scanners, reinforcing the malicious classification. Gridinsoft assigns a trust score of zero out of one hundred, reflecting extreme risk.
The current operational status is offline, and the risk level is elevated. While the page content has not been captured due to the offline state, the combination of registrar information, hosting details, lack of SSL, brand impersonation cues, and multiple vendor detections provides sufficient evidence to treat trustwalletcard.in as a confirmed malicious infrastructure component. Defenders should enforce network‑level blocking of the domain and its resolved IP, monitor for any resurgence, and incorporate the domain into threat‑intel feeds to prevent credential harvesting or crypto‑related fraud attempts.
Inteligência de segurança de rede
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Nextron YARA rules | trustwalletcard.in/assets/index-bakr55ut.js |
malware | Unique code from Jetriz, Swid & Jeniva of the Tetris framework |
| Nextron YARA rules | trustwalletcard.in/assets/index-te6_j_jh.js |
malware | Unique code from Jetriz, Swid & Jeniva of the Tetris framework |
| Quad9 DNS | evmevmevmecmecm.icu |
malicious | Sinkholed |
| DNS4EU | evmevmevmecmecm.icu |
malicious | Sinkholed |
| Hagezi Threat Feed | evmevmevmecmecm.icu |
malicious | Sinkholed |
| DigiCert UltraDNS | tonapi.io |
malicious | Sinkholed |
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Inteligência forense
Análise do VirusTotal
Evidências e relatórios externos
PD-20260211-C77755 Recipient: compliance_abuse@webnic.cc Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo