trust-walllet[.]pages[.]dev
“Trust Wallet: Manage, Swap & Earn Crypto Securely”
已存储的观测记录
观测到的标题差异
证据摘要
trust-walllet.pages.dev has been flagged for active brand impersonation targeting Trust Wallet users, a known cryptocurrency wallet provider. This domain is currently under investigation as part of ongoing SOC monitoring, with confirmed malicious intent to deceive victims into exposing sensitive wallet credentials or initiating unauthorized blockchain transactions. The threat actor leverages Trust Wallet’s reputation to deliver a crypto drainer payload, highlighting the critical need for user vigilance and proactive domain blocking in crypto-related environments. This domain resolves to IP address 172.66.46.230 and is hosted on Cloudflare infrastructure, registered through Cloudflare, Inc. The SSL certificate is issued by Google Trust Services, which may contribute to initial trust perception. As of the latest VirusTotal analysis, the domain remains undetected by 3 out of 95 security vendors, indicating a low detection rate despite clear malicious intent. No presence on public blocklists was observed at time of identification, and creation date analysis suggests recent deployment. The threat is classified as ACTIVE and remains under continuous monitoring for escalation in tactics or infrastructure changes. Mitigation requires immediate network-level and endpoint controls. Block the domain trust-walllet.pages.dev and its resolved IP 172.66.46.230 in DNS and firewall policies. Users should be alerted not to interact with any domain falsely representing Trust Wallet, especially those hosted on Cloudflare Pages (pages.dev). Validate all wallet-related URLs through official Trust Wallet channels. Implement browser extensions that detect crypto drainer domains and enable transaction simulation warnings for outgoing transfers. Security teams should deploy behavioral monitoring for anomalous outbound traffic to known malicious IPs. Regularly audit DNS logs for similar impersonation patterns targeting crypto brands.
Data Coverage
网络安全情报
威胁响应 Pipeline
阻止列表覆盖
监控中的外部数据源 10 个 · 已存快照 2026年8月11日
检测时间线
-
域名状态
可访问 → 无法访问
VirusTotal 分析
网站性能分析
Google PageSpeed Insights — mobile performance audit of trust-walllet.pages.dev · checked Apr 7, 2026
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。
检查任意域名
使用存储的阻止列表、WHOIS、DNS 和公共扫描证据进行威胁分析
立即扫描举报网络钓鱼
将可疑域名提交至我们的威胁数据库——保护社区
报告实时威胁动态
最近的网络钓鱼报告和观察到的可用性变化
监控