trustalabs[.]run
“Trusta $TA Coming”
证据摘要
Analysis of trustalabs.run shows a short-lived infrastructure that was created on February 21, 2026 and is currently taken offline. The domain resolves to the Cloudflare address 172.67.150.152, located in the United States and advertised under ASN 13335. A TLS certificate identified as "WE1" is present, indicating that HTTPS was enabled despite the site’s brief lifespan. The page title returned by the server reads "Trusta $TA Coming," which aligns with the reported scam type of a fake airdrop.
The threat profile lists the target brand as "across," suggesting an attempt to impersonate multiple brands rather than a single named entity. Reputation services rate the host extremely poorly: Gridinsoft assigns a trust score of 0 out of 100, and Scamadviser reports a score of 1 out of 100. VirusTotal records three detections out of ninety‑three scanned engines, confirming that at least a subset of security products flagged the domain as malicious. Independent blocklists, including PhishDestroy and ScamSniffer, have already added the domain to their watchlists, and two additional security blocklists reference it.
The combined evidence points to a coordinated fake‑airdrop campaign that leverages the domain to lure victims with promises of token distribution, as implied by the "$TA" token reference in the title. Defenders should immediately block trustalabs.run at network perimeter devices, update intrusion‑detection signatures with the observed IP and SSL fingerprint, and monitor for newly registered domains that share the same creation window, Cloudflare hosting, or similar title patterns. Continuous ingestion of the listed blocklists will help surface any re‑use of the underlying infrastructure.
Data Coverage
威胁响应 Pipeline
阻止列表覆盖
监控中的外部数据源 10 个 · 已存快照 2026年8月12日
取证情报
VirusTotal 分析
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。
检查任意域名
使用存储的阻止列表、WHOIS、DNS 和公共扫描证据进行威胁分析
立即扫描举报网络钓鱼
将可疑域名提交至我们的威胁数据库——保护社区
报告实时威胁动态
最近的网络钓鱼报告和观察到的可用性变化
监控