trust-wweb3-extension[.]created[.]app
“Trust Wallet Extension - Secure Your Crypto”
Kanıt özeti
The domain trust-wweb3-extension.created.app was registered on February 21, 2026 through Tucows Domains Inc. and is currently listed as offline. Host resolution points to IP address 216.150.1.129, which belongs to Amazon.com, Inc. AS16509 and is geolocated in the United States. The site presents a TLS certificate issued by Let’s Encrypt (R13) and serves HTTP 404 responses, indicating the landing page is not delivering content at the time of analysis. The page title retrieved from the host is “Trust Wallet Extension - Secure Your Crypto,” directly targeting the Trust Wallet brand and matching the reported scam type of a crypto‑related impersonation.
Technical fingerprints show the use of Node.js, React, Next.js, Vercel hosting, Google Cloud services, LaunchDarkly feature flags, HSTS and Google Cloud CDN, consistent with a modern web application stack. The domain appears on one security blocklist and has been blocked by PhishDestroy, confirming that at least one reputable anti‑phishing service has taken remedial action. Gridinsoft assigns a trust score of 0 out of 100, reflecting extreme suspicion. VirusTotal scans report four of ninety‑three security vendors flagging the domain, providing additional independent confirmation of malicious intent.
While the site currently returns a 404, the combination of brand‑targeted page title, low trust score, blocklist presence, and vendor detections strongly suggests an active crypto‑scam infrastructure that was recently taken down. Defenders should continue to monitor the domain and associated IP for any re‑appearance, enforce blocking of the domain in corporate web filters, and educate users about unsolicited Trust Wallet extension prompts. Incident response teams should also review related Vercel and Google Cloud DNS records for potential spill‑over assets, and consider sharing the indicator set with threat‑intelligence sharing platforms to aid broader community protection.
Gönderilen kanıt anlık görüntüsü
- Gönderildi
- Kayıt defteri kayıtları
- 1
- Vaka kimliği
PD-20260125-D2DBEA- PDF belgesi
- PDF kanıtı
Hukuki dayanak
Kanıtın tam metni
Acceptable Use Policy (AUP): The domain trust-wweb3-extension.created.app is engaged in phishing activities, which directly contravenes your AUP prohibiting illegal activities and deception.
Terms of Service (TOS): The use of this domain for fraudulent purposes constitutes a violation of your TOS, which reserves the right to suspend or terminate services for such infractions.
Applicable Laws (Unknown):
Computer Fraud and Abuse Act (CFAA): This U.S. federal law prohibits unauthorized access to computers and networks, which is applicable to phishing schemes.
Wire Fraud Statute (18 U.S.C. § 1343): This law criminalizes schemes to defraud individuals or entities via electronic communications, including phishing.
Anti-Phishing Act (15 U.S.C. § 7704): This act prohibits the use of misleading domain names and deceptive practices in commercial electronic mail messages.
Regulatory Note: Failure to take immediate action against this domain may expose your organization to liability under applicable laws and could result in regulatory scrutiny. It is imperative to act swiftly to mitigate risks associated with domain abuse.
Data Coverage
Tehdit Müdahale Pipeline
Engelleme listesi kapsamı
10 izlenen harici kaynak · kayıtlı anlık görüntü 13.08.2026
Tespit zaman çizelgesi
-
Cloudflare Radar
Cloudflare Radar taraması kaydedildi · Taramayı aç
-
VirusTotal
4 → 5
Kaydedilen görüntü
Etki Alanı Analizi
Teknik ayrıntılarDNS, TLS adları ve zaman damgaları
ICANN OVERSIGHT
Registration: created.app
Akreditasyon ve RAA bağlamı
Akreditasyon ve RAA bağlamı
Registrar accreditation and DNS abuse obligations
For the registrable domain created.app behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Teknolojiler
9 yüksek güvenli teknoloji belirlendi
VirusTotal Analizi
Site Performans Analizi
Google PageSpeed Insights — mobile performance audit of trust-wweb3-extension.created.app · checked Mar 2, 2026
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin