trastwallet[.]co[.]com
“Trust Wallet | Download and Install TrustWallet™ App”
证据摘要
The domain trastwallet.co.com was observed serving a brand‑impersonation site that mimics Trust Wallet. The page title returned by the server is “Trust Wallet | Download and Install TrustWallet™ App”, indicating an attempt to lure users into downloading a counterfeit application. The domain resolves to the IPv4 address 80.64.19.62, which is registered to an Autonomous System (AS48031) operated by Ivan Vitaliy Sergeevich in Poland. WHOIS data shows the registrar is Moniker Online Services LLC and the domain was originally created on 16 August 1997. No TLS certificate is presented, and the site is currently taken offline.
Infrastructure analysis shows the domain is listed on four security blocklists: PhishDestroy, Polkadot, Enkrypt, and Codeesura. VirusTotal reports that 14 of 95 scanned security vendors flagged the domain as malicious, reinforcing the suspicion of a crypto‑scam campaign. The authoritative nameservers are ns1.nic.co.com, ns2.nic.co.com, ns3.nic.co.com and ns4.nic.co.com, which provide no additional mitigation. The threat is classified as a high‑risk crypto scam targeting Trust Wallet users.
Because the site is offline, active probing is limited, and no SSL/TLS information is available to assess certificate misuse. The exact phishing kit or delivery mechanism has not been disclosed, so further forensic collection would be required to determine whether additional payloads or credential‑harvesting forms were hosted. Defenders should block the domain at DNS and network layers, add the four blocklist entries to their threat feeds, and monitor for any future re‑registration of the same second‑level name or similar sub‑domains that could be used for repeat attacks. Continuous observation of the associated IP address and ASN is advised, as the host may be repurposed for other malicious campaigns.
Data Coverage
网络安全情报
威胁响应 Pipeline
阻止列表覆盖
监控中的外部数据源 10 个 · 已存快照 2026年8月11日
检测时间线
VirusTotal 分析
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。
检查任意域名
使用存储的阻止列表、WHOIS、DNS 和公共扫描证据进行威胁分析
立即扫描举报网络钓鱼
将可疑域名提交至我们的威胁数据库——保护社区
报告实时威胁动态
最近的网络钓鱼报告和观察到的可用性变化
监控