MALICIOUS — CRITICAL
Перевірка домену tw-order.live на фішинг і безпеку
tw-order[.]
This domain, tw-order.live, operates as a phishing site specifically targeting users of Trust Crypto Card, a cryptocurrency payment service.
- VirusTotal
- 14/91
- Blocklists
- 2 · MetaMask, SEAL
- Доступність
- Контент недоступний · HTTP 502
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
tw-order.live — Контент недоступний (HTTP 502). Уособлення бренду: Trust Wallet; Тип шахрайства: Crypto Scam. Зведення доказів: VirusTotal 14/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, CRDF); URLScan malicious verdict; Spamhaus DBL_PHISH; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 95/100. Реєстратор: NiceNIC.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
Evidence Analysis
This domain, tw-order.live, operates as a phishing site specifically targeting users of Trust Crypto Card, a cryptocurrency payment service. The site employs deceptive branding and design elements to trick visitors into entering sensitive credentials, such as wallet private keys, recovery phrases, or personal identification details. The intent is to harvest this information for unauthorized access to cryptocurrency accounts or financial fraud. Analysis of the page title, "Trust Crypto Card | Crypto Card," confirms the impersonation of the legitimate service, increasing the likelihood of successful social engineering attacks against unsuspecting users. Infrastructure analysis reveals multiple high-risk indicators. The domain was registered on April 29, 2026, through NICENIC INTERNATIONAL GROUP CO., LIMITED, a registrar frequently associated with malicious domains. It resolves to the IP address 188.114.97.3 and is flagged by 14 out of 95 security vendors on VirusTotal, including detections for phishing and fraudulent activity. Additionally, the domain appears on three security blocklists, and its Gridinsoft trust score is 0/100, further confirming its malicious nature. Technologies detected on the site include Vue.js for dynamic content rendering, Facebook Pixel for tracking user interactions, and Cloudflare for content delivery and DDoS protection, which may obscure the true origin of the malicious activity. Users who have visited tw-order.live or interacted with its content should take immediate action to mitigate potential risks. First, disconnect any wallets or accounts linked to the site and revoke any suspicious permissions granted. Conduct a full scan of the device using updated security tools to detect and remove any malware or unwanted software. Monitor cryptocurrency wallets and financial accounts for unauthorized transactions, and report any suspicious activity to the relevant platform. If credentials were entered, reset passwords and enable multi-factor authentication where possible. Avoid clicking on links from untrusted sources and verify the legitimacy of any cryptocurrency-related communications before taking action.
Stored source results
Recorded verdicts and infrastructure observations for this domain.
Обсяг даних12 recorded checks
Розвіддані з мережевої безпеки Registrar context
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Збережений знімок
Аналітика доменів
Технічні деталіDNS, SAN-адреси SSL, мітки часу
ICANN OVERSIGHT
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Latest Classified Outcome 2026-08-09 01:46:16 UTC
Технології · 5 identified
Vue.js is an open-source model–view–viewmodel JavaScript framework for building user interfaces and single-page applications.
vuejs.org 100% впевненостіFacebook pixel is an analytics tool that allows you to measure the effectiveness of your advertising.
facebook.com 100% впевненостіCloudflare Browser Insights is a tool that measures the performance of websites from the perspective of users.
www.cloudflare.com 100% впевненостіCloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100% впевненостіHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% впевненостіАналіз VirusTotal
Аналіз продуктивності сайту
Google PageSpeed Insights — mobile performance audit of tw-order.live · checked Jun 26, 2026
Докази та зовнішні звітиIndependent lookups and source reports
“Suspected Trust Wallet brand impersonation / cryptocurrency scam landing page. Reported domain: tw-order.live. Reported URL: https://tw-order.live/?utm_medium=paid&utm_source=ig&utm_id=120245694289440503&utm_content=120245694658300503&utm_term=120245694658210503&utm_campaign=120245694289440503&fbclid=PAdGRleARgFp1leHRuA2FlbQEwAGFkaWQBqzLSfb_Dh3NydGMGYXBwX2lkDzEyNDAyNDU3NDI4NzQxNAABp6hj32fprIHEphIq_YMm98ycqW28qdlVzi4iOD5AhEETx2rkZM8tsffw7_kw_aem_OpLDG-RHtpieOfuFsQbCgA. Reported path/query: /?utm_”
PD-20260430-B0D8CE Recipient: abuse@nicenic.net, abuse@identitydigital.com Victim safety and official reportingImmediate actions and verified reporting channels
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.