itrust-capitalogii[.]webflow[.]io
“iTrustCapital Login | Bitcoin Wallet”
itrust-capitalogii.webflow.io — 内容不可用. 品牌冒充:Bitcoin; 诈骗类型:Crypto Scam. 证据摘要: VirusTotal 17/93 (ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, CRDF); URLScan malicious verdict; Google Safe Browsing flagged; CF Radar malicious; PhishDestroy score 95/100. 注册商: NameCheap.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
This domain, itrust-capitalogii.webflow.io, poses a high-risk brand impersonation threat targeting cryptocurrency users. The site presents itself as a legitimate Bitcoin wallet login portal for iTrustCapital, a known cryptocurrency investment platform. Analysis indicates the domain is designed to harvest credentials, potentially leading to unauthorized access to user funds or further exploitation through crypto drainer attacks. The page title, 'iTrustCapital Login | Bitcoin Wallet,' directly mimics official branding to deceive users into entering sensitive login information or private keys, which could result in immediate financial loss or account takeover. Evidence supporting this assessment includes detection by 17 out of 95 security vendors on VirusTotal, indicating widespread recognition of malicious intent. The domain was registered on February 21, 2026, through NameCheap, Inc., a registrar frequently associated with newly created phishing infrastructure. Infrastructure analysis reveals the domain resolves to the IP address 172.64.151.8, hosted on Cloudflare's network (AS13335), a common tactic to obscure the true origin of malicious sites. Additionally, the domain appears on one security blocklist and is flagged by Google Safe Browsing as phishing. The SSL certificate, issued by Google Trust Services (WE1), does not mitigate the risk, as phishing sites often use valid certificates to appear legitimate. Users who have visited itrust-capitalogii.webflow.io or entered credentials on the site should take immediate action to mitigate potential damage. First, revoke any active sessions associated with the account and change passwords for all cryptocurrency-related services, prioritizing those using similar credentials. Enable multi-factor authentication (MFA) where available, using hardware-based or app-based authenticators rather than SMS. Monitor linked accounts for unauthorized transactions and report any suspicious activity to the respective platform. If private keys or recovery phrases were entered, consider the associated wallet compromised and transfer remaining funds to a new, secure wallet. Additionally, scan local devices for malware, as credential theft may be accompanied by secondary payloads. Report the domain to relevant security teams, including cryptocurrency exchanges and anti-phishing organizations, to aid in takedown efforts.
网络安全情报
威胁响应 Pipeline
公共封禁名单状态
所用技术 · 3 identified
Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 置信度 100%HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 置信度 100%VirusTotal 分析
网站性能分析
Google PageSpeed Insights — mobile performance audit of itrust-capitalogii.webflow.io · checked Mar 2, 2026
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。