MALICIOUS — CRITICAL
c[.]gettrustpayment[.]live
16 of 94 security engines flagged the domain; 1 public blocklist listed it (ScamSniffer); the latest stored check returned HTTP 502.
- VirusTotal
- 16/94
- Blocklists
- 1 · ScamSniffer
- sẵn có
- Nội dung không có sẵn · HTTP 502
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
c.gettrustpayment.live — Nội dung không có sẵn (HTTP 502). Mạo danh thương hiệu: Trust Wallet; Loại lừa đảo: Brand Impersonation. Tóm tắt bằng chứng: VirusTotal 16/94 (ADMINUSLabs, alphaMountain.ai, BitDefender, CRDF, Emsisoft); URLQuery 1 alert; URLScan malicious verdict; Spamhaus DBL_PHISH; 1 external blocklist match (ScamSniffer); PhishDestroy score 95/100.
Phân tích chi tiết của PhishDestroy AI bên dưới được giữ bằng tiếng Anh để bảo toàn hồ sơ pháp chứng gốc.
Evidence Digest
c.gettrustpayment.live is classified critical with an evidence score of 95/100. 16 of 94 security engines flagged the domain; 1 public blocklist listed it (ScamSniffer). Registered 4 Apr 2026, hosted on 185.246.190.216 (FlokiNET ehf, NL). The latest stored check on 9 Aug 2026 returned HTTP 502 and includes a capture. 1 outgoing abuse report is recorded, most recently on 4 Apr 2026.
Stored generated summary (templated)mistral · 04/04/2026
Retained for the record. This text repeats stored detection facts and is not presented as authored analysis.
PhishDestroy identifies c.gettrustpayment.live as an active crypto drainer domain posing under the guise of a legitimate payment trust portal. This domain resolves to IP 185.246.190.216 and leverages a Let's Encrypt SSL certificate to appear credible. The site is designed to trick users into connecting crypto wallets under the false pretense of secure payment processing, enabling unauthorized fund transfers once wallet permissions are granted. This domain was flagged with a VirusTotal detection rate of 16/95 engines at the time of analysis, indicating it remains undetected by most antivirus solutions despite its malicious intent. The domain is hosted on a bulletproof hosting provider and uses dynamic DNS through Let's Encrypt for rapid rotation and evasion. With no current blocklist presence and minimal detection, it represents a high-risk threat to users engaging in cryptocurrency transactions. Users who visited c.gettrustpayment.live should immediately disconnect any connected crypto wallets, revoke any granted permissions via blockchain explorers, and scan devices with updated antivirus software. Report the domain to your browser’s safe browsing program and avoid interacting with any payment-related prompts on this site. Consider rotating wallet addresses and private keys if funds were exposed. Proactive monitoring for unauthorized transactions is strongly advised.
Phạm vi dữ liệu12 recorded checks
Tình báo an ninh mạng
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| YARAhub by abuse.ch | c.gettrustpayment.live/scripts/main.js |
malware | Detects file containing Telegram Bot API |
Pipeline ứng phó với các mối đe dọa
Trạng thái trong danh sách chặn công khai
Phân tích của VirusTotal
Phân tích hiệu suất trang
Google PageSpeed Insights — mobile performance audit of c.gettrustpayment.live · checked Apr 4, 2026
Bằng chứng và các báo cáo bên ngoàiIndependent lookups and source reports
PD-20260404-C0D5FC Recipient: abuse@flokinet.is Victim safety and official reportingImmediate actions and verified reporting channels
Nếu bạn đã nhập thông tin xác thực tài khoản, thông tin cá nhân hoặc thông tin thanh toán hoặc đã tải xuống tệp từ miền này, hãy hành động ngay lập tức. Dưới đây là các nguồn lực giúp bạn báo cáo vụ việc và bảo vệ chính mình.
Hãy báo cáo với chính quyền địa phương
Chọn quốc gia của bạn để nhận liên hệ tội phạm mạng chính thức hoặc soạn thảo đơn khiếu nại →.