Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is abuse@ccipanama.com.
The latest stored availability evidence still shows the domain reachable; 1 month has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
wcard[.]to
“WALLESTER — виртуальные карты для рекламы, путешествий, арбитража и крипто-платежей”
wcard.to — Não verificado. Tipo de golpe: Generic Phishing. Resumo das evidências: VirusTotal 5/91 (CRDF, Forcepoint ThreatSeeker, Gridinsoft, Kaspersky, SOCRadar); PhishDestroy score 71/100. Registrador: Government of Kingdom ….
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
Analysis indicates that wcard.to was registered on 27 April 2026 through a registrar linked to the Government of the Kingdom of Tonga. The domain resolves to the IPv4 address 190.97.165.63, which is advertised as being located in Pennsylvania and is announced by AS27956 (Cyber Cast International, S.A.). DNS is served by Cloudflare (gerald.ns.cloudflare.com, summer.ns.cloudflare.com). The site presents a valid TLS certificate from Let’s Encrypt (E7) and returns HTTP 200 responses. Technical fingerprints reveal a stack composed of Ubuntu, Node.js, Nginx, React, Next.js and Webpack, with a Facebook Pixel embedded, suggesting the operators are leveraging a modern web application framework. The visible page title reads “WALLESTER — виртуальные карты для рекламы, путешествий, арбитража и крипто‑платежей”, indicating the site is positioned as a virtual‑card service for advertising, travel, arbitrage and crypto payments, but no further content has been examined. Reputation signals are unfavorable: two of ninety‑one VirusTotal scanners have flagged the domain, Gridinsoft assigns a trust score of 35 / 100, and the domain appears on one public blocklist. PhishDestroy currently lists the site as blocked. The threat rating is marked as high and the operational status is active. Defenders should treat wcard.to as a malicious infrastructure element. Immediate actions include adding the domain and its resolved IP address to outbound and inbound web‑filter policies, updating DNS‑sinkhole or threat‑intel feeds, and monitoring for any credential‑submission traffic directed to the host. Because the underlying service stack is publicly observable, further dynamic analysis of the site’s behavior is advised to confirm the exact phishing payload and any credential‑stealing mechanisms. Continuous re‑evaluation is recommended as additional detections may emerge.
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Tecnologias · 7 identified
Node.js is an open-source, cross-platform, JavaScript runtime environment that executes JavaScript code outside a web browser.
nodejs.org 100% de confiançaUbuntu is a free and open-source operating system on Linux for the enterprise server, desktop, cloud, and IoT.
www.ubuntu.com 100% de confiançaReact is an open-source JavaScript library for building user interfaces or UI components.
reactjs.org 100% de confiançaNginx is a web server that can also be used as a reverse proxy, load balancer, mail proxy and HTTP cache.
nginx.org 100% de confiançaNext.js is a React framework for developing single page Javascript applications.
nextjs.org 100% de confiançaFacebook pixel is an analytics tool that allows you to measure the effectiveness of your advertising.
facebook.com 100% de confiançaAnálise do VirusTotal
Evidências e relatórios externos
“I wanted to open crypto card and transfered 500 Usdt to TD6MRCuSFsBt7k8oaB7ufhDvPrs6ZTc79X (site https://wcard.to/). They said, that it was failure on site and I have to transfer more money.”
PD-20260620-39B61C Recipient: abuse@ccipanama.com Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo