MALICIOUS — HIGH
vtw.cards için kimlik avı ve güvenlik kontrolü
vtw[.]
PhishDestroy identifies vtw.cards as an active credential theft domain associated with a generic phishing campaign.
- VirusTotal
- 3/94
- Blocklists
- No stored match
- Kullanılabilirlik
- İçerik kullanılamıyor · HTTP 502
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
vtw.cards — İçerik kullanılamıyor (HTTP 502). Marka kimliğine bürünme: Trust Wallet; Dolandırıcılık türü: Brand Impersonation. Kanıt özeti: VirusTotal 3/94 (Fortinet, Gridinsoft, SOCRadar); URLScan malicious verdict; Spamhaus DBL_PHISH; PhishDestroy score 65/100. Kayıt kuruluşu: NiceNIC.
Özgün adli kaydı korumak için aşağıdaki ayrıntılı PhishDestroy AI analizi İngilizce bırakılmıştır.
Evidence Analysis
PhishDestroy identifies vtw.cards as an active credential theft domain associated with a generic phishing campaign. Current status remains under investigation following initial detection on March 22, 2026. The domain exhibits characteristics consistent with fraudulent login portals designed to harvest user credentials across unspecified platforms. Security teams are advised to treat this domain as a credible threat vector pending further intelligence updates. This domain was flagged by 3 of 95 VirusTotal vendors as of the latest scan, indicating it remains undetected by conventional security solutions. It resolves to IP address 188.114.97.3 and is registered through NICENIC INTERNATIONAL GROUP CO., LIMITED, using a Let's Encrypt SSL certificate. The domain was created on March 22, 2026, suggesting a recent and potentially opportunistic campaign. Initial trust scores across threat intelligence platforms remain unverified, warranting heightened scrutiny. Current status classifies this domain as active and under investigation, with no confirmed blocklist inclusions at this time. Given the absence of detections and the domain's recent registration, the risk of successful exploitation remains elevated. Immediate containment measures include DNS blocking, SSL certificate revocation requests to Let's Encrypt, and user awareness campaigns highlighting the domain's suspicious attributes. Security teams should also monitor for downstream compromise indicators, such as unauthorized login attempts or credential leaks, associated with accounts handling this domain.
Stored source results
Recorded verdicts and infrastructure observations for this domain.
Veri kapsamı12 recorded checks
Ağ Güvenliği İstihbaratı Registrar context
Tehdit Müdahale Pipeline
Genel Engelleme Listesi Durumu
Kaydedilen görüntü
Etki Alanı Analizi
Teknik ayrıntılarDNS, SSL SAN’ları, zaman damgaları
ICANN OVERSIGHT
Akreditasyon ve RAA bağlamı
Akreditasyon ve RAA bağlamı
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Latest Classified Outcome 2026-08-09 01:46:16 UTC
Teknolojiler · 8 identified
JavaScript runtime built on Chrome V8 engine for server-side development.
JavaScript library for building user interfaces with component-based architecture.
React framework for production with hybrid static and server rendering.
Conversion-tracking pixel by Meta — logs page views and custom events to Facebook/Instagram ad accounts.
www.facebook.comPerformance monitoring tool that measures website speed from real users.
www.cloudflare.comWeb infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comModule bundler for modern JavaScript applications.
Third major version of HTTP protocol, built on QUIC for faster, more reliable connections.
VirusTotal Analizi
Site Performans Analizi
Google PageSpeed Insights — mobile performance audit of vtw.cards · checked Mar 25, 2026
Kanıtlar ve Dış RaporlarIndependent lookups and source reports
PD-20260325-AFE42B Recipient: abuse@nicenic.net, compliance@icann.org Victim safety and official reportingImmediate actions and verified reporting channels
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.