# www.1trx.im — SUSPICIOUS > Beware! www.1trx.im is a crypto drainer phishing site stealing TRX via fake TRON wallet logins. Check now on PhishDestroy — only 0/95 VirusTotal detections so. ## Summary PhishDestroy identifies www.1trx.im as a generic phishing domain operating as a cryptocurrency drainer targeting TRON (TRX) wallet users. The site impersonates a legitimate TRX wallet interface to trick victims into connecting their wallets, resulting in unauthorized fund transfers to attacker-controlled addresses. No specific drainer kit variant has been publicly analyzed yet, but the infrastructure suggests reuse of known phishing toolkits designed for EVM-compatible chains. The domain leverages social engineering tactics such as typosquatting (1trx.im vs tronscan.org) to deceive users seeking TRON blockchain services. This domain resolves to IP 38.54.16.127 and is protected by a Let's Encrypt SSL certificate, which may lend false legitimacy. VirusTotal currently reports 0/95 security vendors detecting the threat as of the latest scan. The domain was registered with Namecheap and shows recent creation activity; however, the exact registration date is not yet confirmed. Google Safe Browsing (GSB) has not yet blacklisted this domain, and no public blocklist entries are recorded. The lack of detections indicates it may be newly deployed or using evasion techniques to bypass initial scans. As of this report, www.1trx.im remains active and under investigation with a risk level categorized as active. No coordinated takedown or response actions have been publicly initiated. The absence of detections on VirusTotal and GSB suggests a window of opportunity for attackers to operate undetected. Users are strongly advised to verify any TRON-related domains using PhishDestroy’s real-time scanning tool and to cross-check URLs against official TRON Foundation resources before entering credentials or connecting wallets. The remaining risk is assessed as medium-high due to the active status and low detection coverage. ## Threat Details - Verdict: SUSPICIOUS - Site status: unknown (HTTP ?) ## Domain Intelligence - Registrar: REGISTRAR_NOT_FOUND - IP: 38.54.16.127 ## Detection Status - VirusTotal: 0 vendors flagged - Google Safe Browsing: clean - Blocklists: 0 hits ## Evidence - Cloudflare Radar: https://radar.cloudflare.com/scan/992e167d-6164-4337-9ffe-bfe47f71cf78 - PhishDestroy: https://phishdestroy.io/domain/www.1trx.im/ - LLM endpoint: https://phishdestroy.io/domain/www.1trx.im/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/www.1trx.im/ Last updated: 2026-03-31