Skip to security report
⚠️
This domain has been flagged as malicious
Security engines reporting a detection: 1. Public blocklists reporting a match: 2. Exercise extreme caution — do not enter credentials or personal information.
Domain security and threat intelligence

trololols[.]online

“TROLL COIN ON SOLANA”

Threat verdict Critical 71/100 evidence score
Availability Content unavailable Content was unavailable in the latest observation
VirusTotal detections: 1/91 Stored blocklist matches: 2 Brand impersonation: Solana
May 7, 2026 Solana 1 Report Sent
Evidence Summary
CRITICAL
Ref
8067090B
Score
71/100

PhishDestroy identifies trololols.online as an active crypto drainer posing as a legitimate wallet sign-in portal, currently under investigation for generic phishing tactics. This domain leverages a Let’s Encrypt SSL certificate for deceptive legitimacy while masking its malicious intent behind a spoofed authentication interface specifically targeting digital asset custodians. Analysts assigned a risk level of “under_investigation” due to limited public blocklist coverage despite zero detections on VirusTotal at the time of assessment, highlighting the evolving nature of credential harvesting campaigns in the crypto space.

This domain was flagged through HOSTINGER operations, UAB registration on May 5 2026, resolving to IP 77.37.34.128. Intelligence shows no current presence on major threat intelligence feeds, with a 1/95 VirusTotal detection ratio as of seed 806709. The use of Let’s Encrypt issuance (common among both benign and malicious sites) combined with a generic TLD (.online) mirrors tactics observed in recent wallet-draining phishing operations targeting users of platforms like MetaMask or Trust Wallet. Technical indicators remain minimal due to the site's early lifecycle and evasive infrastructure choices such as shared hosting platforms known for lax abuse monitoring.

PhishDestroy recommends immediate avoidance of any wallet login prompts accessed via external links from social media, email, or messaging apps. Users who may have entered credentials should revoke connected wallet permissions immediately and transfer remaining assets to a cold wallet not linked to the affected account. If interaction occurred, monitor blockchain transactions and revoke token approvals using tools like Etherscan’s Token Approval tab or DeBank’s approval manager. Report this domain to your wallet provider and share indicators—such as the IP 77.37.34.128 and domain name—with PhishDestroy for inclusion in public threat feeds to help protect others. Always verify site URLs manually and use bookmarked links or official app channels when accessing financial services.

VirusTotal
VirusTotal
1 det.
URLScan
URLScan
ScamAdviser
Scamadviser
14/100
TLS Certificate
Let's Encrypt
Age
3 mo
Observed status
Content unavailable 502
PhishDestroy
DestroyList
Listed
Reports Sent
1
Data coverage VirusTotal 1 / 91 URLQuery checked — no detections recorded PhishStats checked — no match recorded OTX no community references CF Radar scan completed URLScan capture stored report URLScan verdict Analysis completed DNS blocks 14 checked — no blocks TLS valid certificate, 88d WHOIS 3 mo old Screenshot 3 captures · 3 sources Redirect chain not probed Scamadviser 14/100

Threat Response Pipeline

Discovery
Checks
Reports
Availability
14/14
Sent Report Recorded
Stored sent-report record for registrar HOSTINGER operations, UAB, hosting provider, 1 abuse contact
report@abuseradar.com
May 6, 2026

Public Blocklist Status

Stored Capture

Page Title
TROLL COIN ON SOLANA
TLS Certificate
Valid transport encryption · Issued by Let's Encrypt · valid for 88 days

Domain Intelligence

Domain
URLScan Verdict Analysis completed score 0 report ↗
Telegram IoCs 1 extracted https://t.me/trollsolog
Server / ASN LiteSpeed · AS47583 Hostinger International Limited
IP Reputation abuse score 0/100 0 reports checked Jul 13, 2026
Registrar Hostinger LT(LT)
IP Address 77.37.34.128 GB
GeoGB Manchester, GB
NetworkAS47583 · HOSTINGER GB
RegistrationCreated May 5, 2026 (102d)
HTTP Status502 Error
Time to First Unavailability 9 days
What we count Elapsed time from the first stored abuse report to the first observation that the content was unavailable. This does not establish the cause.
What each report contains Stored outgoing-report records may reference evidence available at the time, such as vendor verdicts, registration data, hosting details, classifications, or screenshots. This page does not infer the exact payload delivered, receipt, acknowledgement, or action by a recipient.
Technical detailsDNS, SSL SANs, timestamps
First DetectedMay 7, 2026
IoC Extractionscanned Aug 1, 20260 wallet · 1 Telegram IoC
Submitted URLhttp://trololols.online/
Nameserversapollo.dns-parking.comathena.dns-parking.com
TLS Fingerprint
TLS Observationvalid from May 5, 2026scanned May 7, 2026
TLS SAN Domainswww.trololols.online
Case ID
ICANN OVERSIGHT

Accreditation and RAA context

Registrar accreditation and DNS abuse obligations

For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.

Accreditation is a contract, not a safety certification.

RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.

Accountability draft Nothing is sent automatically.
Technologies · 4 identified
PHP
Programming languages

PHP is a general-purpose scripting language used for web development.

php.net 100% confidence
LiteSpeed
Web servers

LiteSpeed is a high-scalability web server.

litespeedtech.com 100% confidence
Hostinger
Hosting

Hostinger is an employee-owned Web hosting provider and internet domain registrar.

www.hostinger.com 100% confidence
HTTP/3
Miscellaneous

HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.

httpwg.org 100% confidence
Detected via Cloudflare Radar · Wappalyzer engine
Report This Domain Submit evidence & help protect others

VirusTotal Analysis

1 / 91 security vendors flagged this domain
View on VT
Last analyzed
Site Performance Analysis

Google PageSpeed Insights — mobile performance audit of trololols.online · checked May 7, 2026

85
Needs Work
Performance
FCP
3.08s
First Contentful Paint
LCP
3.18s
Largest Contentful Paint
CLS
0
Cumulative Layout Shift
TBT
182ms
Total Blocking Time
SI
3.08s
Speed Index
Powered by Google PageSpeed Insights · Mobile strategy · Scores: 90-100 Good 50-89 Needs Work 0-49 Poor

Evidence & External Reports

Submitted Evidence Snapshot
Sent: Ledger records: 1 Case ID: PD-20260506-5F6247 Recipient: report@abuseradar.com
Page title stored with report: TROLL COIN ON SOLANA
URLScan evidence VirusTotal evidence URLQuery evidence Screenshot 819.5 KB

Were You Affected by This Site?

If credentials were compromised, report immediately. Do not engage with recovery scammers.

If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.

Europol
Find the official reporting channel for your EU country
National police directory
Beware of recovery scammers! Recovery scammers may pose as investigators, lawyers, or tracing services. Do not pay upfront fees or disclose credentials. Learn more about recovery fraud →

Report to Your Local Authorities

Select your country to get official cybercrime contacts, or create a complaint draft →.

97-country directory
Template-based draft • optional AI wording assistance requires separate consent Review and submit it yourself

Check Any Domain

Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence

Scan Now

Report Phishing

Submit suspicious domains to our threat database — protect the community

Report

Live Threat Feed

Recent phishing reports and observed availability changes

Monitor

Stay Informed, Stay Safe

Monitor live threats or contest this listing if you believe it's a false positive

Live Threat Feed Appeal This Listing
HTML · IFRAME

Embed This Report

Share this threat intelligence on your website or blog

embed.html
<iframe
  src="https://phishdestroy.io/embed/domain/trololols.online"
  title="PhishDestroy threat report for trololols.online"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>

A Very Sincere Thank-You Note

Satirical draft generator

Recipient
Fee context

Satirical draft. Fee figures are estimates; exact attribution to this domain is not claimed.