swap[.]trxer[.]org
“USDT ↔ TRX スワップ & TRON エネルギーレンタル|高速 · 安全 · 信頼性”
Zusammenfassung der Beweislage
Analysis of swap.trxer.org, registered on 21 February 2026, indicates a high‑confidence crypto‑related impersonation campaign targeting the Tron ecosystem. The site presented a Japanese‑language page title “USDT ↔ TRX スワップ & TRON エネルギーレンタル|高速 · 安全 · 信頼性”, directly referencing TRX and Tron energy rental, confirming the brand‑impersonation intent. DNS resolution points to 172.67.155.154, an address owned by Cloudflare (AS13335) located in the United States, a common hosting choice for fast‑flux and abuse. The HTTPS certificate is identified as “WE1”, which does not match any known legitimate Tron or exchange authority, further suggesting a fraudulent setup.
The domain is currently offline, but historical scans show that three of ninety‑three VirusTotal scanners flagged the host, and the site appears on a single external blocklist. Gridinsoft assigned a trust score of 0 / 100, indicating extreme malicious confidence. The domain has been added to PhishDestroy’s blocklist, confirming that at least one anti‑phishing service recognized it as a threat. The evidence base is limited to passive DNS, certificate data, and third‑party reputation feeds; no live content or HTTP response was captured after the takedown, so the exact payload, phishing form, or malicious redirects remain unknown.
Defenders should continue to block the IP 172.67.155.154 at the network perimeter, add swap.trxer.org to URL filtering and DNS sinkhole lists, and monitor for any future re‑registration or similar sub‑domains that reuse the “trxer.org” suffix. Security teams handling Tron‑related assets should treat any unsolicited communication referencing USDT‑TRX swaps or energy rentals as suspicious, and users should be instructed to verify URLs against official Tron services. Ongoing telemetry from threat‑intel platforms should be reviewed for new indicators of compromise linked to this seed.
Data Coverage
Pipeline zur Reaktion auf Sicherheitsbedrohungen
Blocklistenabdeckung
10 überwachte externe Feeds · gespeicherter Stand 11.08.2026
VirusTotal-Analyse
Wurden Sie von dieser Website betroffen?
Wenn Sie Kontoanmeldeinformationen, persönliche oder Zahlungsinformationen eingegeben oder eine Datei von dieser Domain heruntergeladen haben, ergreifen Sie sofort Maßnahmen. Nachfolgend finden Sie Ressourcen, die Ihnen helfen, den Vorfall zu melden und sich zu schützen.
Melden Sie sich bei Ihren örtlichen Behörden
Wählen Sie Ihr Land aus, um Offizielle Kontakte im Bereich Cyberkriminalität oder einen Beschwerdeentwurf erstellen → zu erhalten.
Jede beliebige Domain prüfen
Bedrohungsanalyse anhand gespeicherter Blocklisten, WHOIS, DNS und öffentlicher Scan-Beweise
Jetzt scannenPhishing melden
Melden Sie verdächtige Domains an unsere Bedrohungsdatenbank – schützen Sie die Community
MeldenEchtzeit-Bedrohungsfeed
Aktuelle Phishing-Meldungen und beobachtete Verfügbarkeitsänderungen
ÜberwachenBleiben Sie auf dem Laufenden, bleiben Sie sicher
Beobachten Sie aktuelle Bedrohungen oder legen Sie Widerspruch gegen diesen Eintrag ein, wenn Sie der Meinung sind, dass es sich um einen Fehlalarm handelt