trustwalletp2p[.]info
“Trust Wallet - USDT P2P Exchange Platform”
trustwalletp2p.info — Неперевірений. Уособлення бренду: Trust Wallet; Тип шахрайства: Crypto Scam. Зведення доказів: VirusTotal 3/91 (alphaMountain.ai, CRDF, Gridinsoft); PhishDestroy score 65/100.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
Analysis indicates that trustwalletp2p.info has been identified as a brand‑impersonation site targeting TrustWallet users. The domain resolves to the IPv4 address 192.64.80.67, which is hosted by Interserver, Inc. in the United States and is associated with ASN 19318. No TLS certificate is presented, meaning the site is served over plain HTTP, which reduces any perceived legitimacy and also prevents certificate‑based verification. The authoritative name servers are dns2017a.trouble‑free.net and dns2017b.trouble‑free.net, both belonging to a free DNS provider, a pattern often seen in malicious registrations. The page title returned by the web server is “Trust Wallet - USDT P2P Exchange Platform”, directly referencing the TrustWallet brand and suggesting a cryptocurrency peer‑to‑peer exchange service.
The domain has been classified as a “Crypto Scam” in the supplied intelligence and is listed on at least one security blocklist. VirusTotal reports that one out of ninety‑five scanning engines flagged the domain, providing an additional independent indication of malicious intent. PhishDestroy also confirms the site is blocked, and the current operational status is offline, likely as a result of takedown actions. Defenders should treat the domain as hostile infrastructure.
Immediate actions include adding 192.64.80.67 to network blocklists, configuring DNS filtering to deny resolutions of trustwalletp2p.info, and ensuring any endpoint protection solutions ingest the blocklist entry from PhishDestroy. Because the site is inactive, monitoring for re‑registration or re‑appearance of the same host or name server pattern is advisable. Correlation with other observed TrustWallet‑impersonation campaigns may reveal shared tooling or command‑and‑control infrastructure. Until further evidence emerges, the recommendation is to maintain a deny‑by‑default stance for this domain and associated IP, and to alert SOC personnel of the brand‑specific threat vector.
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Аналіз VirusTotal
Архівні докази
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога