trustwalletcards[.]shop
“Trust Wallet Card - Spend Crypto Like Cash”
trustwalletcards.shop — Контент недоступен. Олицетворение бренда: Trust Wallet; Тип мошенничества: Crypto Drainer. Сводка доказательств: VirusTotal 15/91 (alphaMountain.ai, CRDF, ESET, Emsisoft, Forcepoint ThreatSeeker); Spamhaus DBL_PHISH; 3 external blocklist matches (MetaMask, ScamSniffer, SEAL); CF Radar malicious; PhishDestroy score 95/100. Регистратор: PDR.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
The domain trustwalletcards.shop is presently active and resolves to the IP address 162.252.198.162. Its authoritative name servers are dns1.regway.com, dns2.regway.com, dns3.regway.com, and dns4.regway.com, indicating registration through the RegWay DNS service. The domain has been flagged by multiple security vendors: four of ninety‑five VirusTotal scanners have identified it as malicious, and it is listed on three external blocklists.
Defensive products such as PhishDestroy, MetaMask, and SEAL have already added the domain to their block lists, suggesting that the site is being used to target cryptocurrency users, consistent with its classification as a crypto drainer. No public information is available regarding the site’s SSL certificate, HTTP response codes, or page title, and no additional intelligence on the hosting provider, ASN, or geographic location has been disclosed. Because the domain is actively resolving and is already recognized by major anti‑phishing and wallet protection tools, defenders should continue to block any traffic to trustwalletcards.shop at network perimeter and endpoint layers.
Security teams should also monitor the associated IP address 162.252.198.162 for any new malicious activity, and consider adding the host to internal threat intelligence feeds. Ongoing observation of DNS changes for the listed RegWay name servers is recommended, as any alteration may indicate a shift in infrastructure. The limited detection footprint—four vendor flags and three blocklist entries—highlights the need for rapid containment while additional analysis, such as content retrieval and certificate inspection, is performed to fully characterize the threat vector.
Данные сетевой безопасности
Процесс реагирования на угрозы
Статус в публичных блок-листах
Сохранённый снимок
Аналитика доменов
Технические сведенияDNS, SAN в протоколе SSL, временные метки
ICANN OVERSIGHT
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Технологии · 3 identified
Ubuntu is a free and open-source operating system on Linux for the enterprise server, desktop, cloud, and IoT.
www.ubuntu.com 100% уверенностиNginx is a web server that can also be used as a reverse proxy, load balancer, mail proxy and HTTP cache.
nginx.org 100% уверенностиFacebook pixel is an analytics tool that allows you to measure the effectiveness of your advertising.
facebook.com 100% уверенностиАнализ VirusTotal
Архивные доказательства
Доказательства и внешние отчеты
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание