trustwalletinvests[.]org
“TrustWallet Invest - Your Trusted Investment Partner”
证据摘要
Analysis of trustwalletinvests.org indicates a high‑confidence brand‑impersonation attempt targeting users of the Trust Wallet cryptocurrency wallet. The domain was registered on 21 February 2026 through Hostinger operations, UAB, and uses the generic parking nameservers ns1.dns-parking.com and ns2.dns-parking.com. DNS resolution points to the IPv4 address 92.113.23.46, which belongs to AS47583 Hostinger International Limited and is geolocated in Germany. No Transport Layer Security certificate is presented for the host, confirming that the site does not serve HTTPS content. The page title returned from the now‑offline site reads “TrustWallet Invest – Your Trusted Investment Partner,” which explicitly references the Trust Wallet brand and suggests an investment or financial service, consistent with the listed crypto‑scam classification.
The domain has been added to at least one security blocklist and was flagged by the PhishDestroy takedown service, confirming that active mitigation actions have been taken. VirusTotal scans show that seven of ninety‑three antivirus engines flagged the domain as malicious, providing additional independent corroboration of its illicit nature. The current HTTP status is offline, limiting real‑time interaction but preserving evidence of the malicious infrastructure. Uncertainty remains regarding the specific payload or phishing kit employed, as no detailed page content or capture of login forms has been publicly released.
The absence of an SSL certificate and the use of a generic parking provider suggest a low‑cost, disposable deployment rather than a sophisticated, persistent operation. Defenders should update their domain‑blocking feeds to include trustwalletinvests.org, monitor the associated IP address 92.113.23.46 for any future hosting changes, and consider adding the ASN AS47583 to watchlists for related activity.
已提交证据快照
- 已发送
- 台账记录
- 1
- 案件 ID
PD-20260211-B12A6D- 已捕获页面标题
- TrustWallet Invest - Your Trusted Investment Partner
- PDF 文件
- PDF 证据
完整证据文本
Section 3.1 of the Acceptable Use Policy: The domain trustwalletinvests.org is engaged in phishing activities, attempting to deceive users into providing sensitive information under the guise of a legitimate service.
Section 4.2 of the Terms of Service: The use of this domain constitutes a violation of the terms regarding fraudulent and deceptive practices, warranting immediate action to suspend or terminate services.
Applicable Laws (Unknown):
Computer Fraud and Abuse Act (CFAA): This U.S. federal law prohibits unauthorized access to computers and networks, which is applicable as phishing schemes often involve unauthorized access to personal data.
Wire Fraud Statute (18 U.S.C. § 1343): This law criminalizes schemes to defraud individuals through electronic communications, which is relevant given the fraudulent nature of the phishing activities associated with this domain.
Anti-Phishing Act: This legislation targets deceptive practices aimed at acquiring sensitive information, directly applicable to the operations of trustwalletinvests.org.
Regulatory Note: Failure to take appropriate action against this domain may expose your organization to legal liability and regulatory scrutiny. Immediate compliance is essential to mitigate potential risks.
Data Coverage
威胁响应 Pipeline
阻止列表覆盖
监控中的外部数据源 10 个 · 已存快照 2026年8月11日
检测时间线
-
Cloudflare Radar
已存储 Cloudflare Radar 扫描 · 打开扫描
已保存的截图
域名情报
技术详情DNS、TLS 名称和时间戳
ICANN OVERSIGHT
认证和 RAA 背景
认证和 RAA 背景
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
VirusTotal 分析
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。
检查任意域名
使用存储的阻止列表、WHOIS、DNS 和公共扫描证据进行威胁分析
立即扫描举报网络钓鱼
将可疑域名提交至我们的威胁数据库——保护社区
报告实时威胁动态
最近的网络钓鱼报告和观察到的可用性变化
监控