trustproducts[.]shop
“Crypto Card — Issue Your Crypto Card Instantly”
Kanıt özeti
PhishDestroy identifies trustproducts.shop as an active crypto drainer domain impersonating a trusted products service. The threat actor leverages social engineering to trick users into connecting crypto wallets, where a drainer script silently transfers funds to attacker-controlled addresses. No specific drainer kit fingerprint has been publicly documented for this domain, but its behavior aligns with common JavaScript-based drainers that monitor wallet connections and execute unauthorized transfers upon approval. The domain does not mimic a specific major brand but instead capitalizes on generic “trust” and “products” terminology to appear legitimate in phishing campaigns targeting cryptocurrency users.
Technical indicators confirm this domain’s malicious nature. As of the latest scan, trustproducts.shop resolves to 104.21.65.243 and is protected by a Let's Encrypt SSL certificate. VirusTotal detection stands at only 1 out of 95 security vendors, indicating low signature coverage. The domain was registered recently and is likely intended for short-lived campaigns. While exact creation date and registrar details are not confirmed, the low detection rate and active resolution suggest it is being actively used in the wild. Google Safe Browsing (GSB) status is currently unlisted, and the domain appears on two threat intelligence blocklists. These factors collectively point to a newly deployed, stealthy operation with minimal footprint.
This domain remains active and poses an elevated risk to cryptocurrency users. Immediate actions include network-level blocking via DNS sinkholing or firewall rules targeting IP 104.21.65.243 and the domain itself. Users should be warned against visiting the site and advised to verify all wallet connection prompts carefully. Given the low detection rate and lack of widespread awareness, this threat has potential to grow. Continuous monitoring is advised, and organizations are urged to update threat intelligence feeds and endpoint protections. Remaining risk is elevated due to the domain’s active status and minimal detection coverage.
Data Coverage
Tehdit Müdahale Pipeline
Engelleme listesi kapsamı
10 izlenen harici kaynak · kayıtlı anlık görüntü 13.08.2026
Kaydedilen görüntü
Etki Alanı Analizi
Teknik ayrıntılarDNS, TLS adları ve zaman damgaları
ICANN OVERSIGHT
Akreditasyon ve RAA bağlamı
Akreditasyon ve RAA bağlamı
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Teknolojiler
7 yüksek güvenli teknoloji belirlendi
VirusTotal Analizi
Site Performans Analizi
Google PageSpeed Insights — mobile performance audit of trustproducts.shop · checked Apr 21, 2026
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin