trustwallets[.]ru
“trustwallets.ru”
Resumo das evidências
On 24 July 2026 the domain trustwallets.ru was observed as part of an elevated‑risk brand‑impersonation campaign targeting Trust Wallet users. The domain was registered on 21 February 2026 and currently resolves to the IPv4 address 91.98.153.192, which is hosted in Germany within the Cloud Fsn1 infrastructure. The authoritative name servers are ns18.hostia.name and ns17.hostia.name, and the domain’s MX record points to trustwallets.ru with priority 10, indicating a self‑hosted mail setup. The page title returned by the web server is the literal string “trustwallets.ru”, but no further content analysis is available because the site has been taken offline. VirusTotal has recorded detections from ten of ninety‑three scanning engines, confirming the presence of malicious components.
AlienVault OTX lists the domain in a single threat pulse, and the domain appears on one public blocklist. PhishDestroy has actively blocked the domain, reinforcing its classification as a crypto‑related scam. The scam type is explicitly identified as “Crypto Scam”, suggesting attempts to lure victims into fraudulent cryptocurrency transactions under the guise of the Trust Wallet brand. Available evidence does not disclose SSL certificate details, Safe Browsing status, or any additional reputation scores. Consequently, defenders should treat the domain as malicious and incorporate the IP address 91.98.153.192 and the two host‑names into blocklists and intrusion detection signatures.
Network traffic to the domain or its mail server should be inspected for anomalous authentication attempts or phishing‑related payloads. Because the site is offline, continuous monitoring of the hoster (Hostia) for re‑registration of similar variants is advised. Analysts should also verify any inbound emails that reference trustwallets.ru, as the MX record may have been used for phishing communications.
Data Coverage
Inteligência de segurança de rede
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Hagezi Threat Feed | trustwallets.ru |
malicious | Sinkholed |
| DNS0 Zero | trustwallets.ru |
malicious | Sinkholed |
Pipeline de resposta a ameaças
Cobertura de listas de bloqueio
10 fontes externas monitoradas · instantâneo de 11/08/2026
10 fontes externas monitoradas Sem correspondência
Análise do VirusTotal
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo