app.trustrawallet.com
“TrustraWallet”
www.app.trustrawallet.com is identified as a crypto drainer with 5 of 95 VirusTotal vendors flagging it and listed on one security blocklist, indicating.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
Сводка доказательств
The domain www.app.trustrawallet.com has been identified as a crypto drainer, associated with activities aimed at extracting cryptocurrency from unsuspecting users. There is no specific brand associated with this domain, but its malicious infrastructure indicates it is part of a broader scheme targeting digital wallet users. The domain's online presence raises significant concerns regarding user security and trust.
Technical indicators for www.app.trustrawallet.com reveal a VirusTotal (VT) score of 4 out of 95, meaning that while not all security vendors flag it, a notable minority does recognize the potential threat. The domain was created on March 22, 2026, and is registered through TuringSign Inc., operating under the name Cosmotown. The domain resolves to the IP address 198.251.89.168, and it is currently blocked by one security blocklist, showing its recognition as a threat. According to information from Google Safe Browsing (GSB), the domain is listed, which contributes to its elevated risk assessment.
Currently, the status of www.app.trustrawallet.com is offline, likely due to proactive response actions taken by security entities. However, it is essential to maintain vigilance since the domain may reappear or be relaunched through different infrastructure. The existing risk remains elevated as the potential for future operations targeting cryptocurrency holders exists. Users and network administrators are advised to block this domain and remain cautious of any communications or links associated with it to prevent possible financial loss.
Forensic History & Detection Timeline
-
VirusTotal Detections Update Jul 1, 2026 · 04:55 UTCVirusTotal scanner detections updated from 1 to 4. Added scanner alerts: ChainPatrol, Fortinet, alphaMountain.ai.
Процесс реагирования на угрозы
Статус в публичных блок-листах
Evasion analysis
Cloaking suspected: scanner and victim titles differ
Stored crawler-versus-browser observations for this host, plus a live fingerprint check for Keitaro-style traffic distribution systems.
- Stored cloaking flag
- Not observed
- Оценка маскировки
- 0/6
- Last cloaking scan
- Server header seen by scanner
LiteSpeed
Scanner note: redirect: raw=redirect_302; http=302; via=https_proxy; location=https://www.app.trustrawallet.com/login; server=LiteSpeed
Технологии · 6 identified
Анализ VirusTotal
Доказательства и внешние отчеты
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание