trip71[.]top
“TripScan | ТрипСкан”
证据摘要
PhishDestroy identifies trip71.top as an active crypto-drainer domain crafted to impersonate Trip.com, leveraging homographic and lookalike techniques to trick users into connecting fraudulent cryptocurrency wallets. The landing page closely mirrors Trip.com’s branding, including color scheme and layout, while injecting malicious JavaScript payloads designed to drain connected wallets upon user interaction. No specific drainer kit fingerprint is yet confirmed, but the domain’s rapid registration and SSL issuance suggest opportunistic deployment of off-the-shelf phishing toolkits.
Technical indicators for trip71.top are as follows: VirusTotal detection rate is 4/95 engines, indicating zero coverage as of the latest scan. The domain is registered via NICENIC INTERNATIONAL GROUP CO., LIMITED, resolves to IP 188.114.97.3, and was created on March 23, 2026. The SSL certificate was issued by Let’s Encrypt, and no Google Safe Browsing (GSB) block has been applied at this time. No third-party blocklist entries were found during initial checks.
Current status of trip71.top is active and propagating, with no detections or blocks in place. Immediate response includes adding the domain and its resolving IP to enterprise blocklists and DNS sinkholes. Users should be warned not to access trip71.top or any Trip.com lookalike domains not served directly from trip.com or its official CDN. The risk remains under investigation but is assessed as elevated due to the combination of zero detection, recent creation, and clear intent to deceive. Continuous monitoring and proactive user education are recommended to prevent wallet compromise.
已提交证据快照
- 已发送
- 台账记录
- 1
- 案件 ID
PD-20260407-5C7667- 已捕获页面标题
- TripScan | ТрипСкан
- PDF 文件
- PDF 证据
完整证据文本
Policy Violations: “Services may be used only for lawful purposes… fraud, abuse and illegal activity prohibited. Violations may result in immediate suspension.” + dedicated abuse handling and takedown
Applicable Laws: Crimes Ordinance Cap.200 (Fraud), Theft Ordinance Cap.210 §16A (fraud by deception), Personal Data (Privacy) Ordinance Cap.486
Data Coverage
网络安全情报
威胁响应 Pipeline
阻止列表覆盖
监控中的外部数据源 10 个 · 已存快照 2026年8月12日
检测时间线
-
VirusTotal
None → 1
已保存的截图
域名情报
技术详情DNS、TLS 名称和时间戳
ICANN OVERSIGHT
认证和 RAA 背景
认证和 RAA 背景
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
取证情报
VirusTotal 分析
网站性能分析
Google PageSpeed Insights — mobile performance audit of trip71.top · checked May 28, 2026
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。
检查任意域名
使用存储的阻止列表、WHOIS、DNS 和公共扫描证据进行威胁分析
立即扫描举报网络钓鱼
将可疑域名提交至我们的威胁数据库——保护社区
报告实时威胁动态
最近的网络钓鱼报告和观察到的可用性变化
监控