trustusdt.online
“SEND USDT”
The domain trustusdt.online is currently active and serves a generic phishing campaign as indicated by its classification.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
Сводка доказательств
The domain trustusdt.online is currently active and serves a generic phishing campaign as indicated by its classification. Registration data shows the domain was created through GoDaddy.com, LLC, and it is served by the authoritative name servers ns37.domaincontrol.com and ns38.domaincontrol.com, both typical of GoDaddy‑hosted domains. An HTTP request to the root URL returns a 200 OK status, confirming that a web service is reachable.
VirusTotal analysis reports that five out of ninety‑one security vendors have flagged the domain, suggesting that at least a minority of scanners have identified malicious characteristics. The domain is listed on a single external security blocklist and is actively blocked by the PhishDestroy mitigation service, providing additional evidence of its abuse. No public page title or SSL certificate details have been disclosed, and the underlying hosting IP address, geographic location, or TLS configuration remain unverified in the available data.
Consequently, defenders should treat any traffic to trustusdt.online as potentially hostile. Recommended actions include adding the domain to local deny lists, updating intrusion‑prevention signatures to cover the observed hostnames, and monitoring DNS queries for the associated name servers. Continuous re‑evaluation is advised, as additional detection signals may emerge from further scanning or community reporting.
Данные сетевой безопасности
Forensic History & Detection Timeline
-
Threat First Observed Jul 28, 2026 · 19:33 UTCDomain ingestion complete. Initial state is marked as alive.
Процесс реагирования на угрозы
Статус в публичных блок-листах
Evasion analysis
Cloaking & traffic-distribution check
Stored crawler-versus-browser observations for this host, plus a live fingerprint check for Keitaro-style traffic distribution systems.
- Stored cloaking flag
- Not yet scanned
- Last cloaking scan
Scanner note: timeout: raw=timeout; http=0; via=http_proxy; error=HTTPConnectionPool(host='82.29.233.80', port=7937): Read timed out. (read timeout=7)
Сохранённый снимок · 1 source
Аналитика доменов
Технические деталиDNS, SAN в протоколе SSL, временные метки
ICANN OVERSIGHT
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Анализ VirusTotal
Сообщения сообщества
Сообщил 1 участник сообщества; впервые замечено 30.05.2026
- Сохранённые сообщения
- 1
- Уникальные URL
- 1
Доказательства и внешние отчеты
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание