Перейти до звіту про безпеку
Безпека домену та аналіз загроз
trues.foundation favicon

trues.foundation

“True Foundation”

Реєстратор
Porkbun
Resolved IP
190.123.45.35
Registered
06.09.2025
Загрозливий вердикт Високий
Доступність Останній відомий активний Раніше недоступний; останнє спостереження було доступним Спостережуване
Source: HTTP probe
Виявлення VirusTotal: 3/95 Збережений список блокувань відповідає: 1 Уособлення бренду: Binance
19.09.2025 Binance
API
Цей домен було позначено як шкідливий
Системи безпеки повідомляють про виявлення: 3. Публічні списки блокувань, які повідомляють про збіг: 1. Будьте дуже обережні — не вводьте облікові дані чи особисту інформацію.
Огляд звіту

trues.foundation — Останній відомий активний (HTTP 200). Уособлення бренду: Binance; Тип шахрайства: Fake Airdrop. Зведення доказів: VirusTotal 3/95 (alphaMountain.ai, Forcepoint ThreatSeeker, Gridinsoft); 1 external blocklist match (ScamSniffer); PhishDestroy score 69/100. Реєстратор: Porkbun.

Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.

VirusTotal
VirusTotal
3 det.
URLScan
URLScan
Вік
1.1 yr
Зафіксований статус
Останній відомий активний 200
PhishDestroy
DestroyList
У списку

Source evidence

7 sources

Блокування DNS

14 перевірено — блокувань немає

Google Safe Browsing

Checked; no threat flag recorded

Повідомити
Розвіддані з мережевої безпеки
SSL Certificate Invalid
SSL certificate is invalid or expired. Issuer:

Зведення доказів

Високий
VirusTotal
3/95
URLScan
Stored capture

This domain is flagged for elevated-risk brand impersonation targeting Binance, a major cryptocurrency exchange platform. Analysis indicates the site masquerades as an official Binance-affiliated foundation, likely designed to deceive users into disclosing credentials or transferring assets under false pretenses. The specific threat type—brand impersonation—exploits trust in the targeted entity to facilitate fraudulent activities, including potential cryptocurrency theft or credential harvesting. Infrastructure analysis reveals the domain trues.foundation was registered on September 06, 2025, through Porkbun LLC, a registrar frequently associated with newly created suspicious domains. The domain resolves to the IP address 190.123.45.35, which has no prior association with legitimate Binance infrastructure. Detection metrics indicate 3 out of 95 security vendors on VirusTotal flagged the domain as malicious, while it appears on two independent security blocklists. Additional trust scoring from Gridinsoft assigns a score of 0 out of 100, further corroborating its high-risk classification. The page title, 'True Foundation,' attempts to lend legitimacy to the operation, though no such entity is officially linked to Binance. Mitigation measures for this threat type include immediate domain blacklisting at the network perimeter and endpoint levels. Organizations should update security policies to block domains registered within the last 30 days through high-risk registrars, particularly those resolving to IPs with no prior legitimate use. Users should be educated to verify domain authenticity via official channels before interacting with any Binance-related foundation or promotional site. Cryptocurrency asset holders are advised to enable multi-factor authentication and verify transaction requests through secondary, trusted communication methods. Monitoring for newly registered domains impersonating financial entities remains critical to preempting similar campaigns.

Extracted from stored page analysis

Observed indicators

0 wallet · 1 Telegram

Full extracted values, their blockchain and collection source. An address found in page content does not establish who controls it.

Telegram
https://t.me/truetradingaiStored page reference

IoC extraction recorded 2026-08-02 04:38:53 UTC

Аналіз виявлення та ухилення

Підозра на маскування: заголовки сканера та відвідувача відрізняються

Не спостерігалося У збереженому скані не було виявлено жодних слідів маскування

Збережені дані спостережень за взаємодією веб-сканера та браузера для цього хоста, а також перевірка відбитків у режимі реального часу для систем розподілу трафіку типу «Кейтаро».

Збережений прапор маскування
Не спостерігалося
Оцінка маскування
0/6
Останнє сканування маскування
Заголовок сервера, який бачить сканер
openresty

Примітка щодо сканера: expired: raw=parked; http=200; via=https_proxy; server=openresty

Назва, що відображається на сканері безпекиporkbun.com | domain for sale
Заголовок, що відображається відвідувачеві веб-браузераTrue Foundation
Перевірка відбитків пальців у режимі реального часу за адресою TDS
Сім відбитків Keitaro та порівняння «краулер проти браузера», що запускаються зі сканера PhishDestroy, коли ця панель відкрита.
Очікування

Збережений знімок · 2 captures

Заголовок сторінки
True Foundation
Impersonates
Binance Bybit Chatgpt Foundation Phantom Solana

Domain details

Домен
URLScan Verdict Аналіз завершено score 0 report ↗
Репутація IP abuse score 0/100 0 reports checked 18.06.2026
РеєстраціяСтворено 06.09.2025 — Expires 06.09.2026
Elapsed Since First Report 235 days
Що ми враховуємо Raw elapsed time since the first stored abuse report. It is not a registrar response-time measurement. Latest observed status: Останній відомий активний.
Що містить кожен звіт Збережені записи вихідних звітів можуть посилатися на докази, доступні на той час, наприклад вердикти постачальників, реєстраційні дані, деталі хостингу, класифікації або знімки екрана. Ця сторінка не визначає точного доставленого корисного навантаження, квитанції, підтвердження чи дії одержувача.
Статус HTTP200
Технічні подробиціProvenance & timestamps
Вперше виявлено19.09.2025
DOM Analysisanalyzed 23.04.2026score 50/1006 brand signals
IoC Extractionscanned 02.08.20260 wallet · 1 Telegram IoC
Submitted URLhttps://trues.foundation/
ICANN OVERSIGHT

Акредитація та контекст RAA

Registrar accreditation and DNS abuse obligations

For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.

Accreditation is a contract, not a safety certification.

RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.

Accountability draft Нічого не надсилається автоматично.

Network & certificates

Stored technical evidence

Network & DNS

Resolved IP
190.123.45.35
Network ASN
AS52284
Organization
Panamaserver.com
Observed location
Panamá, PA
Server header
LiteSpeed

Сервери імен 2

  • ns1cp52.panamaserver.com
  • ns2cp52.panamaserver.com

Location describes the IP network.

viewdns.info · 190.123.45.35rapiddns.io

Latest Classified Outcome 2026-10-11 01:10:38 UTC

Primary outcome Неактивний reason: Expired Landing Page 60% confidence
Attribution mechanism: Lifecycle Notice Page source: Current Http Probe
Evidence layers Availability: Non Threat Content Content: Replaced Or Parked DNS: Resolved Registration: Unknown
Latest HTTP observation Неактивний Expired Landing Page Lifecycle Notice Page 60% 2026-10-11 01:10:38 UTC
RDAP registration Невідомо
Observed timeline last reachable: 2026-06-16 22:10:46 UTC current episode first observed: 2026-10-01 01:25:34 UTC observed RIP window: 2026-06-16 22:10:46 UTC → 2026-10-01 01:25:34 UTC · 2,547.25h midpoint estimate ≈ 2026-08-08 23:48:10 UTC · precision very low · basis bounded
Availability, content, DNS and registration are independent evidence layers. NXDOMAIN, an unreachable origin or missing content alone does not prove registrar action. A registrar or provider is credited only when a direct technical marker identifies that actor. Report causality is shown separately.
Поскаржитися на цей домен Надішліть докази та допоможіть захистити інших

Аналіз VirusTotal

3 / 95 постачальників безпеки позначили цей домен
View on VT
Last analyzed Previous stored snapshot: 3 detections
alphaMountain.ai
Forcepoint ThreatSeeker
Gridinsoft

Forensic History & Detection Timeline

ThreatLifecycleTelemetry
This timeline displays historical security and status checkpoints observed by the PhishDestroy automated monitoring network. It records domain lifecycle updates, scanner changes, and threat telemetry over time.
  1. VirusTotal Detections Update 2026-06-27 03:56:08 UTC
    VirusTotal scanner detections updated from 3 to 3. Added scanner alerts: Gridinsoft. Resolved alerts: G-Data.
  2. Cloudflare Radar Scan 2026-03-07 16:48:30 UTC
    Cloudflare Radar scan registered: View Radar report.

Процес реагування на загрози Pipeline

Відкриття
Analysis
Monitoring

10 recorded events. These records describe collected evidence, outgoing notifications and publication; they do not confirm a complete investigation or a takedown.

Загроза виявлена
trues.foundation виявлено та додано до черги для повного аналізу
19.09.2025
URLScan.io Capture
Збережено URLScan report with capture artifacts
05.03.2026
Cloudflare Radar Report
A stored Cloudflare Radar report is available. The report link alone is not a malicious verdict and does not prove that every network field was captured.
VirusTotal
3/95 recorded on VirusTotal
27.06.2026
Виявлення списків блокування
Знайдено в 1 blocklist: ScamSniffer
11.10.2026
Brand Impersonation
Impersonation of Binance
Forensic Evidence Collected
Stored evidence from URLScan.io, stored screenshot
05.03.2026
Technical Analysis Recorded
Звіт містить збережені результати технологічного або криміналістичного аналізу.
11.10.2026
Cloudflare Radar Scan
Скановано за допомогою Cloudflare Radar; аналіз мережі завершено.
07.03.2026
Опубліковано список «DestroyList»
19.09.2025
Monitoring Continues
Домен залишається доступним або обмеженим; майбутні перевірки можуть оновити це спостереження.
How we investigate & report

Public scans, evidence and abuse channels

We scan suspicious URLs, inspect public results and send evidence through the appropriate abuse-reporting channels. The dated events above show what is recorded for this domain. The directory below explains the wider workflow.

01Public scans & evidence collection10 sources and tool groups
urlscan.io Screenshot · DOM · HTTP

Capture the rendered page, requests and visible infrastructure.

VirusTotal Multi-engine verdicts

Compare the available engine results and retain the analysis timestamp.

Cloudflare Radar DNS · certificates · categories

Inspect a public scan and its recorded network and classification data.

AlienVault OTX Threat-intelligence pulses

Look for indicator references and related community intelligence.

Wayback Machine Historical evidence

Compare archived captures and preserve historical context.

crt.sh Certificate Transparency

Inspect certificate records and related hostnames.

DNS Security Filters Quad9 · AdGuard · CleanBrowsing

Compare security resolver responses and record observed blocking.

Web-Check Surface inspection

Inspect the public DNS, TLS, HTTP and technology surface.

02Abuse reports & follow-upRegistrar, hosting and security channels
  1. Identify the responsible provider. Match registration and hosting records to the relevant abuse contact.
  2. Prepare an evidence package. Include the URL, public scan references, captures and the recorded observations.
  3. Send the report. Keep outgoing report records and recipient information when available.
  4. Recheck and publish updates. Track later scanner verdicts, provider responses and site availability.

Security services used for scanning, reputation checks and reporting are listed below. A service being listed is not evidence that it received, accepted or acted on this particular domain. Recorded submissions appear in the notification history above.

Статус у публічних блоклистах

Схожі домени

Збережено 187 схожих доменів

Показати всі (88)
binabce.com replacement binacne.com transposition binan.ce.com subdomain binancecom.com various binanci.com vowel-swap binanco.com vowel-swap binancr.com replacement binancs.com replacement binancw.com replacement binande.com replacement binanfe.com replacement binanve.com replacement binanxe.com replacement binnace.com transposition binonce.com vowel-swap binsnce.com replacement binunce.com vowel-swap binynce.com replacement binznce.com replacement bniance.com transposition bunance.com replacement ibnance.com transposition ninance.com replacement b-inance.com hyphenation b8inance.com insertion b8nance.com replacement b9nance.com replacement bbinance.com repetition bhinance.com insertion bi-nance.com hyphenation biance.com omission bibance.com replacement bibnance.com insertion bihance.com replacement bihnance.com insertion biinance.com repetition bijnance.com insertion biknance.com insertion bimance.com homoglyph bimnance.com insertion bin-ance.com hyphenation binaance.com repetition binabnce.com insertion binace.com omission binahce.com replacement binamnce.com insertion binan-ce.com hyphenation binanbce.com insertion binanc-e.com hyphenation binanc.com omission binanc3.com replacement binancce.com repetition binancve.com insertion binancxe.com insertion binancz.com replacement binandce.com insertion binane.com omission binanec.com homoglyph binanhce.com insertion binanmce.com insertion binannce.com homoglyph binanvce.com insertion binanxce.com insertion binarnce.com homoglyph binasnce.com insertion binawnce.com insertion binbance.com insertion binhance.com insertion binmance.com insertion binnance.com homoglyph binnce.com omission binqance.com insertion binsance.com insertion binwnce.com replacement binyance.com insertion bionance.com insertion birnance.com homoglyph biunance.com insertion bjnance.com replacement bnance.com omission bninance.com insertion boinance.com insertion bonance.com replacement buinance.com insertion bvinance.com insertion clinance.com homoglyph dinarce.com homoglyph ginance.com replacement

Показано 100 із 187

Повідомлення спільноти

Повідомив 1 учасник спільноти; уперше помічено 19.09.2025

Збережені повідомлення
1
Унікальні URL
1
Прийнято1

Докази та зовнішні звіти

Глибокий аналіз

Чи вплинув на вас цей сайт?

4 evidence signal groups linked 0 reports recorded Останній відомий активний
If credentials were compromised, report immediately. Do not engage with recovery scammers.

Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.

Європол
Знайдіть офіційний канал звітності для вашої країни ЄС
National police directory
Остерігайтеся шахраїв, які обіцяють повернути втрачені кошти! Злочинці можуть знову зв’язатися з жертвами, видаючи себе за слідчих, адвокатів або агентів із відновлення. Не сплачуйте авансових зборів і не діліться обліковими даними. Дізнайтеся більше про шахрайство у сфері відшкодування збитків →

Зверніться до місцевих органів влади

Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.

Довідник 97 країн

Template-based draft · optional AI wording assistance requires separate consent

Чернетка за допомогою штучного інтелекту — деталі інциденту обробляються постачальником штучного інтелекту · Перегляньте та подайте його самостійно

Перевірити будь-який домен

Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування

Сканувати зараз

Повідомити про фішинг

Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту

Повідомити

Потокова стрічка про загрози

Останні звіти про фішинг і помічені зміни доступності

Відстежувати

Будьте в курсі подій, дбайте про свою безпеку

Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога

Потокова стрічка про загрози Оскаржити це оголошення
HTML · IFRAME

Вбудувати цей звіт

Поділіться цією інформацією про загрози на своєму веб-сайті або в блозі

embed.html
<iframe
  src="https://phishdestroy.io/uk/embed/domain/trues.foundation"
  title="PhishDestroy threat report for trues.foundation"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>