verify[.]t3rn[.]run
Análisis de phishing y seguridad de verify.t3rn.run
“t3rn | Check Your BRN for TRN Airdrop Eligibility”
verify.t3rn.run — Contenido no disponible (HTTP 502). Tipo de estafa: Crypto Scam. Resumen de las pruebas: VirusTotal 2/93 (G-Data, Gridinsoft); 1 external blocklist match (ScamSniffer); PhishDestroy score 58/100.
El análisis detallado de PhishDestroy AI se mantiene en inglés para conservar el registro forense original.
verify.t3rn.run is a subdomain of t3rn.run. PhishDestroy first observed the hostname on Feb 26, 2026. The hostname uses “verify,” a pattern consistent with a account-verification lure; no target brand is confirmed from stored content. The captured page title is “t3rn | Check Your BRN for TRN Airdrop Eligibility”. Stored page analysis classifies the content as crypto scam. Campaign clustering links the hostname to the Airdrop Scam kit. Current evidence score: 58/100 (high).
Positive findings are stored from 2 sources: VirusTotal and ScamSniffer. VirusTotal recorded 2 detections among 93 engines: G-Data, Gridinsoft on Feb 25, 2026 at 00:55 UTC. ScamSniffer listed the hostname in the separate external-blocklist snapshot on Aug 8, 2026 at 06:20 UTC. Non-positive and contextual checks: Google Safe Browsing returned no flag on Mar 3, 2026 at 04:14 UTC. URLScan completed without a malicious verdict (score 0) on Jul 29, 2026 at 03:20 UTC.
HTTP 502 was recorded on Aug 7, 2026 at 01:27 UTC; content was unavailable. The recorded creation date for the registrable domain t3rn.run is Feb 21, 2026. Registration preceded first observation by 5 days. At collection time, the hostname resolved to 172.67.167.223 on AS13335 (CLOUDFLARENET, US). The IP and ASN identify shared Cloudflare edge infrastructure; the origin server is not established by this address. DOM analysis on Mar 23, 2026 at 23:17 UTC returned 56/100. The evidence archive retains 2 visual captures from PhishDestroy and URLScan. TLS metadata lists WE1 as the certificate issuer.
The content indicators and 2 positive source findings support the current crypto scam classification.
Proceso de respuesta ante amenazas Pipeline
Estado de la lista de bloqueados pública
Análisis de VirusTotal
Datos y informes externos
¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.