tw-card[.]com
“Trust | Your Private Crypto Card”
证据摘要
The domain tw-card.com was registered on 9 February 2026 through Global Domain Group LLC. Its authoritative name servers are bryce.ns.cloudflare.com and lana.ns.cloudflare.com, indicating use of Cloudflare’s DNS service. DNS resolution points to the IP address 188.114.97.3, which belongs to AS13335 Cloudflare, Inc. and is geolocated in the United States. The site operates without an SSL/TLS certificate, exposing traffic to potential interception despite Cloudflare’s edge network. HTTP/3 support is detected, confirming modern protocol usage. The page title returned from the host is “Trust | Your Private Crypto Card”, and the threat classification is a crypto‑related brand impersonation targeting the Trust Wallet brand.
The campaign has been catalogued as a crypto scam. Independent threat‑intelligence feeds have placed tw‑card.com on four security blocklists, specifically PhishDestroy, MetaMask, ScamSniffer, and SEAL. VirusTotal analysis shows that fifteen of ninety‑five scanned scanners raise a detection, reinforcing the malicious assessment. Current operational status is offline, suggesting the infrastructure has been taken down or is no longer serving content.
However, the presence of the domain on multiple blocklists and the VirusTotal detections provide sufficient evidence for continued monitoring. Defenders should block DNS resolution for the domain and its associated IP address, enforce TLS inspection rules to detect the lack of encryption, and add the domain to internal blocklists. Network‑level controls should also deny traffic to the Cloudflare name servers when they resolve to the identified IP, and security teams should update phishing‑protection products with the observed page title and brand impersonation indicator. Ongoing vigilance is advised in case the actor resurrects the site under a new domain or reuses the same hosting infrastructure.
已提交证据快照
- 已发送
- 台账记录
- 1
- 案件 ID
PD-20260214-7442F3- 已捕获页面标题
- Trust | Your Private Crypto Card
- PDF 文件
- PDF 证据
完整证据文本
Acceptable Use Policy (AUP): The domain tw-card.com is engaged in phishing activities, which directly contravenes the prohibition against illegal activities and fraud as outlined in your AUP.
Terms of Service (TOS): The ongoing use of this domain for deceptive practices constitutes a violation of your TOS, which reserves the right to suspend or terminate services for such infractions.
Applicable Laws (Unknown):
Computer Fraud and Abuse Act (CFAA): This U.S. federal law prohibits unauthorized access to computers and the use of phishing schemes to deceive individuals.
Wire Fraud Statute (18 U.S.C. § 1343): This law criminalizes schemes to defraud individuals using electronic communications, including phishing.
Anti-Phishing Consumer Protection Act: This legislation aims to combat phishing by imposing penalties on those who engage in deceptive practices to obtain sensitive information.
Regulatory Note: Failure to take immediate action against tw-card.com may expose your organization to legal liabilities and regulatory scrutiny. Compliance with your AUP and TOS is essential to mitigate risks associated with hosting fraudulent domains.
Data Coverage
网络安全情报
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| OpenDNS | tw-card.com |
phishing | Phishing Block |
| DNS4EU | tw-card.com |
malicious | Sinkholed |
| OpenDNS | id2107.tw-card.com |
phishing | Phishing Block |
| DNS4EU | id2107.tw-card.com |
malicious | Sinkholed |
| OpenDNS | id2518.tw-card.com |
phishing | Phishing Block |
| DNS4EU | id2518.tw-card.com |
malicious | Sinkholed |
威胁响应 Pipeline
阻止列表覆盖
监控中的外部数据源 10 个 · 已存快照 2026年8月10日
检测时间线
已保存的截图
域名情报
技术详情DNS、TLS 名称和时间戳
ICANN OVERSIGHT
认证和 RAA 背景
认证和 RAA 背景
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
VirusTotal 分析
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。
检查任意域名
使用存储的阻止列表、WHOIS、DNS 和公共扫描证据进行威胁分析
立即扫描举报网络钓鱼
将可疑域名提交至我们的威胁数据库——保护社区
报告实时威胁动态
最近的网络钓鱼报告和观察到的可用性变化
监控