buy-tron[.]workers[.]dev
Análisis de phishing y seguridad de buy-tron.workers.dev
“USDT to TRX Swap & TRON Energy Rental | Fast, Secure, Reliable”
buy-tron.workers.dev — Contenido no disponible (HTTP 502). Suplantación de marca: Tron; Tipo de estafa: Crypto Scam. Resumen de las pruebas: VT 0 det. (total unavailable); URLQuery 0; URLScan no malicious verdict; GSB no flag; BL 2 (MetaMask, SEAL); PD 66/100. Registrador: Cloudflare.
El análisis detallado de PhishDestroy AI se mantiene en inglés para conservar el registro forense original.
buy-tron.workers.dev is a tenant hostname on Cloudflare, not a separately registered domain. PhishDestroy first recorded this hostname on Feb 26, 2026. The hostname explicitly references Tron; stored content metadata identifies the same apparent target. Content analysis also recorded brand signals for Trust Wallet. The stored content classification is crypto scam. The assembled evidence scores 66/100 (elevated).
Two independent sources are positive: MetaMask and SEAL. MetaMask and SEAL listed the hostname in the external-blocklist snapshot on Aug 7, 2026 at 18:20 UTC. The evidence is not unanimous. URLQuery recorded no positive detection. Google Safe Browsing returned no flag on Mar 2, 2026 at 21:06 UTC. URLScan completed without a malicious verdict (score 0) on Mar 25, 2026 at 11:43 UTC. VirusTotal was checked, but a reliable engine total is unavailable on Jul 18, 2026 at 18:45 UTC.
HTTP 502 was recorded on Aug 7, 2026 at 01:01 UTC; content was unavailable. Cloudflare is the hosting platform for this tenant, not its registrar. At collection time, the hostname resolved to 188.114.97.3 on AS13335 (CLOUDFLARENET - Cloudflare, Inc., US). The associated network metadata labels the endpoint as AS13335 Cloudflare, Inc. in San Francisco, US. This is shared platform infrastructure; the IP and ASN are hosting context, not attribution to unrelated tenants. The stored server header is cloudflare. Captured page title: “USDT to TRX Swap & TRON Energy Rental | Fast, Secure, Reliable”. DOM analysis completed on Jul 29, 2026 at 04:09 UTC; stored DOM score 0/100. The evidence archive retains 2 visual captures from PhishDestroy and URLScan. IoC extraction completed on Aug 1, 2026 at 04:26 UTC; stored 0 format-validated wallet addresses and 0 Telegram indicators.
The 0/100 DOM score means that the DOM pass stored no scored indicators; it does not negate the independent source findings. Taken together, the page content and independent findings support classifying this hostname as Tron-themed crypto scam.
Proceso de respuesta ante amenazas Pipeline
Estado de la lista de bloqueados pública
Datos y informes externos
¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.