xn--trz-lddi9c[.]xn--mwalletsuite-3fk4b0756gga[.]tr0-wallet[.]com
“KEVIN DWAYNE PUCKETT — Leather Trezor Accessories”
xn--trz-lddi9c.xn--mwalletsuite-3fk4b0756gga.tr0-wallet.com — Непроверенный. Олицетворение бренда: Trezor; Тип мошенничества: Brand Impersonation. Сводка доказательств: VirusTotal 11/91 (ADMINUSLabs, BitDefender, CyRadar, ESET, Fortinet); URLQuery 1 alert; Spamhaus DBL_SPAM; PhishDestroy score 89/100. Регистратор: Hello Internet.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
PhishDestroy identifies the domain tr0-wallet.com as an active crypto drainer under investigation, using seed cf5897. This domain mimics a legitimate wallet suite and poses a direct threat to users’ digital assets by coercing cryptocurrency transfers through deceptive interfaces.
This domain resolves to IP 91.215.85.162, was registered through Hello Internet Corp on February 05, 2026, and holds a Let's Encrypt SSL certificate. VirusTotal currently reports 1/95 detections, indicating it remains undetected by many security engines, and no blocklist entries have been recorded as of this analysis. The domain has not been flagged by Google Safe Browsing (GSB) at this time, highlighting a critical window of exposure for potential victims.
As of this report, the domain is classified as active with a risk level of under_investigation. PhishDestroy has flagged this domain for its association with crypto drainer activity and continues to monitor its behavior. Users are strongly advised to avoid interacting with tr0-wallet.com or any subdomains. Security teams should block IP 91.215.85.162 and monitor network traffic for connections to this domain. The absence of detections and blocklist entries suggests elevated risk, warranting immediate caution and proactive blocking to prevent potential asset loss.
Данные сетевой безопасности
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | www.xn--trz-lddi9c.xn--mwalletsuite-3fk4b0756gga.tr0-wallet.com |
malicious | Sinkholed |
Процесс реагирования на угрозы
Статус в публичных блок-листах
Сохранённый снимок
Аналитика доменов
Технические сведенияDNS, SAN в протоколе SSL, временные метки
ICANN OVERSIGHT
Registration: tr0-wallet.com
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For the registrable domain tr0-wallet.com behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Технологии · 1 identified
High-performance HTTP server and reverse proxy, known for stability and low resource usage.
Анализ VirusTotal
Анализ производительности сайта
Google PageSpeed Insights — mobile performance audit of xn--trz-lddi9c.xn--mwalletsuite-3fk4b0756gga.tr0-wallet.com · checked Mar 30, 2026
Доказательства и внешние отчеты
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание