trustwalletcard[.]in
“Trust Wallet - Crypto Card”
trustwalletcard.in — Контент недоступний (HTTP 502). Уособлення бренду: Ethereum; Тип шахрайства: Crypto Scam. Зведення доказів: VirusTotal 4/93 (Fortinet, Gridinsoft, SOCRadar, URLQuery); URLQuery 6 alerts; Spamhaus DBL_PHISH; 3 external blocklist matches (MetaMask, ScamSniffer, SEAL); PhishDestroy score 74/100. Реєстратор: Web Commerce Communica….
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
The domain trustwalletcard.in was registered on February 21, 2026 through Web Commerce Communications Limited and is hosted on Cloudflare infrastructure, resolving to IP address 104.21.56.96 located in the United States under ASN 13335 (Cloudflare, Inc.). The authoritative nameservers are bryce.ns.cloudflare.com and elinore.ns.cloudflare.com. No TLS certificate is presented for the domain, indicating that connections are served without encryption. The site’s page title, "Trust Wallet - Crypto Card," and the listed brand target of Ethereum suggest an attempt to impersonate the Trust Wallet brand and the broader Ethereum ecosystem.
Threat intelligence classifies the activity as a crypto scam, and the domain appears on four independent security blocklists. Multiple anti‑phishing services—including PhishDestroy, MetaMask, ScamSniffer, and SEAL—have identified and blocked the site. VirusTotal analysis reports four positive detections out of ninety‑three scanners, reinforcing the malicious classification. Gridinsoft assigns a trust score of zero out of one hundred, reflecting extreme risk.
The current operational status is offline, and the risk level is elevated. While the page content has not been captured due to the offline state, the combination of registrar information, hosting details, lack of SSL, brand impersonation cues, and multiple vendor detections provides sufficient evidence to treat trustwalletcard.in as a confirmed malicious infrastructure component. Defenders should enforce network‑level blocking of the domain and its resolved IP, monitor for any resurgence, and incorporate the domain into threat‑intel feeds to prevent credential harvesting or crypto‑related fraud attempts.
Розвіддані з мережевої безпеки
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Nextron YARA rules | trustwalletcard.in/assets/index-bakr55ut.js |
malware | Unique code from Jetriz, Swid & Jeniva of the Tetris framework |
| Nextron YARA rules | trustwalletcard.in/assets/index-te6_j_jh.js |
malware | Unique code from Jetriz, Swid & Jeniva of the Tetris framework |
| Quad9 DNS | evmevmevmecmecm.icu |
malicious | Sinkholed |
| DNS4EU | evmevmevmecmecm.icu |
malicious | Sinkholed |
| Hagezi Threat Feed | evmevmevmecmecm.icu |
malicious | Sinkholed |
| DigiCert UltraDNS | tonapi.io |
malicious | Sinkholed |
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Криміналістичні дані
Аналіз VirusTotal
Докази та зовнішні звіти
PD-20260211-C77755 Recipient: compliance_abuse@webnic.cc Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога