MALICIOUS — CRITICAL
io-trast.pages.dev için kimlik avı ve güvenlik kontrolü
io-trast[.]
Analysis of the domain io-trast.pages.dev, created on March 22, 2026, shows a clear pattern of brand impersonation targeting Trust Wallet.
- VirusTotal
- 4/94
- Blocklists
- 2 · MetaMask, SEAL
- Kullanılabilirlik
- Ulaşılabilir · erişim kısıtlı · HTTP 403
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
io-trast.pages.dev — Ulaşılabilir · erişim kısıtlı (HTTP 403). Marka kimliğine bürünme: Trust Wallet; Dolandırıcılık türü: Crypto Scam. Kanıt özeti: VirusTotal 4/94 (ChainPatrol, alphaMountain.ai, LevelBlue, Phishing Database); 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 71/100. Kayıt kuruluşu: Cloudflare.
Özgün adli kaydı korumak için aşağıdaki ayrıntılı PhishDestroy AI analizi İngilizce bırakılmıştır.
Evidence Analysis
Analysis of the domain io-trast.pages.dev, created on March 22, 2026, shows a clear pattern of brand impersonation targeting Trust Wallet. The site served a page titled “How to Use Trust Wallet: Guide to Crypto,” which aligns with the declared crypto‑scam classification. Technical profiling indicates the domain is hosted behind Cloudflare’s network (nameservers adaline.ns.cloudflare.com and dimitris.ns.cloudflare.com) and resolves to IP address 188.114.97.3, an address owned by Cloudflare, Inc. in Canada.
The TLS certificate is issued by Google Trust Services under the WE1 root, confirming the use of a legitimate certificate authority, while HTTP/3 and HSTS are enabled, suggesting an effort to mimic legitimate services. VirusTotal scans returned four positive detections out of ninety‑four vendors, and the domain appears on three external blocklists, with active takedown actions reported by PhishDestroy, MetaMask, and SEAL. The site currently returns HTTP 403 and has been taken offline, but historical evidence indicates it was used to lure users into a Trust Wallet‑related cryptocurrency guide, a typical vector for credential harvesting or fund diversion.
Gridinsoft’s trust score of 0 / 100 further underscores the malicious nature of the infrastructure. Defenders should continue to block the IP 188.114.97.3 and the domain at the DNS level, update intrusion‑prevention signatures to include the observed page title and the specific Cloudflare nameserver pair, and monitor for newly registered domains that resolve to the same Cloudflare IP range with similar Trust Wallet‑related titles. Given the brand impersonation, threat intelligence feeds should flag any future attempts to replicate this pattern, and user‑education campaigns should remind Trust Wallet users that official guidance is delivered only through verified channels.
Stored source results
Recorded verdicts and infrastructure observations for this domain.
Veri kapsamı12 recorded checks
Ağ Güvenliği İstihbaratı
Tehdit Müdahale Pipeline
Genel Engelleme Listesi Durumu
Adli İstihbarat
Teknolojiler · 3 identified
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
VirusTotal Analizi
Site Performans Analizi
Google PageSpeed Insights — mobile performance audit of io-trast.pages.dev · checked Mar 21, 2026
Kanıtlar ve Dış RaporlarIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.