tronlink.info
“TronLink 钱包 | 波场钱包 | 超过10000000 全球用户的可靠选择”
The domain tronlink.info was registered on February 21, 2026 through GoDaddy.com, LLC.
Die ausführliche Analyse von PhishDestroy AI bleibt auf Englisch, damit der ursprüngliche forensische Bericht unverändert bleibt.
Zusammenfassung der Beweislage
The domain tronlink.info was registered on February 21, 2026 through GoDaddy.com, LLC. It is currently active and returns an HTTP 301 redirect. The page title presented by the site is “TronLink 钱包 | 波场钱包 | 超过10000000 全球用户的可靠选择”, which references a cryptocurrency wallet service. The intelligence categorizes the site as a crypto‑related phishing operation, matching the generic_phishing threat type.
Infrastructure analysis shows the domain resolves to the IPv4 address 103.251.113.250, hosted in Hong Kong and advertised under AS133380 (Layerstack Limited). The authoritative name servers are ns1.cloud-dns-inc.com and ns2.cloud-dns-inc.com. The web server stack comprises Nginx serving a WordPress installation backed by MySQL and PHP, with client‑side libraries including jQuery and fullPage.js. Additional services such as MailChimp and HTTP Strict Transport Security (HSTS) are detected, and the SSL certificate is identified as R13.
Reputation signals are strongly negative. VirusTotal records six out of ninety‑five AV engines flagging the domain as malicious, and the Gridinsoft trust score is 0 out of 100. The domain appears on a single security blocklist and is actively blocked by PhishDestroy. The combination of a low trust score, multiple vendor detections, and the crypto‑wallet branding in the page title supports a high‑risk classification.
Defenders should treat tronlink.info as a high‑risk indicator and enforce blocking at network perimeter and endpoint levels. Continuous monitoring of DNS queries for the domain and its associated IP address is advised, as well as inclusion in internal phishing and malware blocklists. Because the public content of the site has not been examined, any additional payload or credential‑harvesting mechanisms remain uncertain; analysts should consider sandboxing any retrieved pages before allowing user interaction.
Forensic History & Detection Timeline
-
Cloudflare Radar Scan Mar 2, 2026 · 22:00 UTCCloudflare Radar scan registered: View Radar report.
Pipeline zur Reaktion auf Sicherheitsbedrohungen
Status der öffentlichen Sperrliste
Evasion analysis
Cloaking suspected: scanner and victim titles differ
Stored crawler-versus-browser observations for this host, plus a live fingerprint check for Keitaro-style traffic distribution systems.
- Stored cloaking flag
- Not observed
- Cloaking-Wert
- 0/6
- Last cloaking scan
- Server header seen by scanner
nginx
Scanner note: alive_content: raw=content_403; http=403; via=http_proxy; server=nginx
Technologien · 9 identified
VirusTotal-Analyse
Community-Erkenntnisse
1 Community-Meldung
KategoriePHISHING
Detection Summary The Anti-Phishing Volunteers & Associates Security Incident Response System has flagged this as a domain threat, classified as phishing attack against TronLink. Threat detected at 2026-03-01T15:46:47.357Z.
Community-Meldungen
Von 1 Community-Mitglied gemeldet; erstmals gesehen am 13.02.2026
- Gespeicherte Meldungen
- 1
- Eindeutige gemeldete URLs
- 1
Nachweise und externe Berichte
Wurden Sie von dieser Website betroffen?
Wenn Sie Kontoanmeldeinformationen, persönliche oder Zahlungsinformationen eingegeben oder eine Datei von dieser Domain heruntergeladen haben, ergreifen Sie sofort Maßnahmen. Nachfolgend finden Sie Ressourcen, die Ihnen helfen, den Vorfall zu melden und sich zu schützen.
Melden Sie sich bei Ihren örtlichen Behörden
Wählen Sie Ihr Land aus, um Offizielle Kontakte im Bereich Cyberkriminalität oder einen Beschwerdeentwurf erstellen → zu erhalten.
Jede beliebige Domain prüfen
Bedrohungsanalyse anhand gespeicherter Blocklisten, WHOIS, DNS und öffentlicher Scan-Beweise
Jetzt scannenPhishing melden
Melden Sie verdächtige Domains an unsere Bedrohungsdatenbank – schützen Sie die Community
MeldenEchtzeit-Bedrohungsfeed
Aktuelle Phishing-Meldungen und beobachtete Verfügbarkeitsänderungen
ÜberwachenBleiben Sie auf dem Laufenden, bleiben Sie sicher
Beobachten Sie aktuelle Bedrohungen oder legen Sie Widerspruch gegen diesen Eintrag ein, wenn Sie der Meinung sind, dass es sich um einen Fehlalarm handelt