The domain trxfee.store is currently active and has been identified as a generic phishing infrastructure. Technical investigation shows that the domain resolves to the IP address 188.114.97.3 and is delegated to Cloudflare nameservers finley.ns.cloudflare.com and gabriella.ns.cloudflare.com. The domain has been added to one security blocklist and is explicitly blocked by the PhishDestroy service, indicating that at least one independent mitigation platform has deemed it malicious.
VirusTotal reports that the domain was scanned by 91 antivirus and URL‑reputation vendors; none of the vendors returned a positive detection, but the absence of a detection does not constitute validation of safety. The available intelligence does not provide a page title, brand target, or detailed content analysis, so the precise phishing payload and the intended victim set remain unknown. Given the combination of active resolution, inclusion on a blocklist, and the presence of a dedicated blocklisting entry, defenders should treat trxfee.store as a high‑confidence malicious indicator.
Recommended actions include adding the domain and its resolved IP address to network‑level deny lists, configuring DNS‑based filtering to block queries, and monitoring for any new resolution or hosting changes. Continuous re‑evaluation is advised, as further analysis of the landing page or associated traffic could reveal additional indicators of compromise.