trusts-card[.]com
“Phantom Card | Spend Crypto Anywhere”
Kanıt özeti
Analysis of trusts-card.com, registered through Hello Internet Corp on 2026-03-11, shows a typical brand‑impersonation infrastructure targeting the Phantom brand. The domain resolves to IP 104.21.60.143, an address owned by AS13335 Cloudflare, Inc. in the United States, and is served behind Cloudflare’s reverse‑proxy service using HTTP/3. DNS is delegated to ezra.ns.cloudflare.com and jocelyn.ns.cloudflare.com, indicating a standard Cloudflare DNS configuration. The site employed a Node.js stack with Vue.js and Nuxt.js, and included third‑party trackers such as Facebook Pixel and Cloudflare Browser Insights, confirming the presence of modern web technologies but providing no indication of malicious code.
A Let’s Encrypt E8 certificate secured the site, which is typical for short‑lived malicious domains. VirusTotal records show three of ninety‑four scanning engines flag the domain, and PhishDestroy has already added it to its blocklist; it also appears on one additional security blocklist. The page title “Phantom Card | Spend Crypto Anywhere” directly references the targeted brand, confirming the impersonation intent.
The site is currently offline, so active payload delivery cannot be verified. Defenders should continue to block the domain at DNS and proxy layers, monitor for any re‑hosting attempts on alternative IP ranges, and educate users that any unsolicited request to acquire a “Phantom Card” for cryptocurrency spending is likely fraudulent. Ongoing vigilance is advised, especially given the elevated risk rating and the observed use of reputable cloud services to obscure the attacker’s origin.
Data Coverage
Ağ Güvenliği İstihbaratı
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| YARAhub by abuse.ch | trusts-card.com/ |
malware | Detects file containing Telegram Bot API |
Tehdit Müdahale Pipeline
Engelleme listesi kapsamı
10 izlenen harici kaynak · kayıtlı anlık görüntü 11.08.2026
Kaydedilen görüntü
Etki Alanı Analizi
Teknik ayrıntılarDNS, TLS adları ve zaman damgaları
ICANN OVERSIGHT
Akreditasyon ve RAA bağlamı
Akreditasyon ve RAA bağlamı
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
VirusTotal Analizi
Site Performans Analizi
Google PageSpeed Insights — mobile performance audit of trusts-card.com · checked Mar 11, 2026
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin