trxrent[.]io
“ÐÑенда ÑнеÑгии TRX и обмен USDT | ÐвÑомаÑиÑеÑÐºÐ°Ñ Ð¾ÑпÑавка …”
Stored observation
Observed title contrast
Evidence Summary
Analysis of trxrent.io indicates a high-risk phishing domain targeting cryptocurrency users, specifically those interacting with TRX (Tron) and USDT (Tether) transactions. The domain was registered on March 28, 2026, and remains active as of July 12, 2026. Its page title, rendered in Russian, translates to 'TRX Energy Rental and USDT Exchange | Automatic Sending | trxRent.io,' suggesting an intent to deceive users into engaging with fraudulent crypto services. The domain resolves to IP address 188.114.96.3, which has been associated with 23 threat intelligence pulses on AlienVault OTX. It is currently listed on two security blocklists, including PhishDestroy and BLP-Malware. Three out of 95 security vendors on VirusTotal have flagged trxrent.io as malicious, though the absence of broader detection does not confirm safety. The domain holds a Gridinsoft trust score of 0/100, reinforcing its classification as untrustworthy. Infrastructure analysis reveals the use of a Let's Encrypt SSL certificate, a common tactic among phishing domains to appear legitimate. No evidence of a known phishing kit or specific brand impersonation has been confirmed beyond the page title's reference to TRX and USDT. Defenders should treat this domain as actively malicious, block resolution at the network level, and monitor for connections or credential submissions linked to it. Further investigation into associated wallet addresses or transaction patterns is recommended to assess potential financial impact.
Data Coverage
Threat Response Pipeline
Blocklist coverage
10 monitored external feeds · stored snapshot Aug 12, 2026
10 monitored external feeds No match
Technologies
3 high-confidence technologies identified
VirusTotal Analysis
Site Performance Analysis
Google PageSpeed Insights — mobile performance audit of trxrent.io · checked Jul 13, 2026
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive