trustwalletcard[.]in
“Trust Wallet - Crypto Card”
trustwalletcard.in — Контент недоступен (HTTP 502). Олицетворение бренда: Ethereum; Тип мошенничества: Crypto Scam. Сводка доказательств: VirusTotal 4/93 (Fortinet, Gridinsoft, SOCRadar, URLQuery); URLQuery 6 alerts; Spamhaus DBL_PHISH; 3 external blocklist matches (MetaMask, ScamSniffer, SEAL); PhishDestroy score 74/100. Регистратор: Web Commerce Communica….
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
The domain trustwalletcard.in was registered on February 21, 2026 through Web Commerce Communications Limited and is hosted on Cloudflare infrastructure, resolving to IP address 104.21.56.96 located in the United States under ASN 13335 (Cloudflare, Inc.). The authoritative nameservers are bryce.ns.cloudflare.com and elinore.ns.cloudflare.com. No TLS certificate is presented for the domain, indicating that connections are served without encryption. The site’s page title, "Trust Wallet - Crypto Card," and the listed brand target of Ethereum suggest an attempt to impersonate the Trust Wallet brand and the broader Ethereum ecosystem.
Threat intelligence classifies the activity as a crypto scam, and the domain appears on four independent security blocklists. Multiple anti‑phishing services—including PhishDestroy, MetaMask, ScamSniffer, and SEAL—have identified and blocked the site. VirusTotal analysis reports four positive detections out of ninety‑three scanners, reinforcing the malicious classification. Gridinsoft assigns a trust score of zero out of one hundred, reflecting extreme risk.
The current operational status is offline, and the risk level is elevated. While the page content has not been captured due to the offline state, the combination of registrar information, hosting details, lack of SSL, brand impersonation cues, and multiple vendor detections provides sufficient evidence to treat trustwalletcard.in as a confirmed malicious infrastructure component. Defenders should enforce network‑level blocking of the domain and its resolved IP, monitor for any resurgence, and incorporate the domain into threat‑intel feeds to prevent credential harvesting or crypto‑related fraud attempts.
Данные сетевой безопасности
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Nextron YARA rules | trustwalletcard.in/assets/index-bakr55ut.js |
malware | Unique code from Jetriz, Swid & Jeniva of the Tetris framework |
| Nextron YARA rules | trustwalletcard.in/assets/index-te6_j_jh.js |
malware | Unique code from Jetriz, Swid & Jeniva of the Tetris framework |
| Quad9 DNS | evmevmevmecmecm.icu |
malicious | Sinkholed |
| DNS4EU | evmevmevmecmecm.icu |
malicious | Sinkholed |
| Hagezi Threat Feed | evmevmevmecmecm.icu |
malicious | Sinkholed |
| DigiCert UltraDNS | tonapi.io |
malicious | Sinkholed |
Процесс реагирования на угрозы
Статус в публичных блок-листах
Криминалистическая аналитика
Анализ VirusTotal
Доказательства и внешние отчеты
PD-20260211-C77755 Recipient: compliance_abuse@webnic.cc Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание