tronlink.info
“TronLink 钱包 | 波场钱包 | 超过10000000 全球用户的可靠选择”
The domain tronlink.info was registered on February 21, 2026 through GoDaddy.com, LLC.
El análisis detallado de PhishDestroy AI se mantiene en inglés para conservar el registro forense original.
Resumen de las pruebas
The domain tronlink.info was registered on February 21, 2026 through GoDaddy.com, LLC. It is currently active and returns an HTTP 301 redirect. The page title presented by the site is “TronLink 钱包 | 波场钱包 | 超过10000000 全球用户的可靠选择”, which references a cryptocurrency wallet service. The intelligence categorizes the site as a crypto‑related phishing operation, matching the generic_phishing threat type.
Infrastructure analysis shows the domain resolves to the IPv4 address 103.251.113.250, hosted in Hong Kong and advertised under AS133380 (Layerstack Limited). The authoritative name servers are ns1.cloud-dns-inc.com and ns2.cloud-dns-inc.com. The web server stack comprises Nginx serving a WordPress installation backed by MySQL and PHP, with client‑side libraries including jQuery and fullPage.js. Additional services such as MailChimp and HTTP Strict Transport Security (HSTS) are detected, and the SSL certificate is identified as R13.
Reputation signals are strongly negative. VirusTotal records six out of ninety‑five AV engines flagging the domain as malicious, and the Gridinsoft trust score is 0 out of 100. The domain appears on a single security blocklist and is actively blocked by PhishDestroy. The combination of a low trust score, multiple vendor detections, and the crypto‑wallet branding in the page title supports a high‑risk classification.
Defenders should treat tronlink.info as a high‑risk indicator and enforce blocking at network perimeter and endpoint levels. Continuous monitoring of DNS queries for the domain and its associated IP address is advised, as well as inclusion in internal phishing and malware blocklists. Because the public content of the site has not been examined, any additional payload or credential‑harvesting mechanisms remain uncertain; analysts should consider sandboxing any retrieved pages before allowing user interaction.
Forensic History & Detection Timeline
-
Cloudflare Radar Scan Mar 2, 2026 · 22:00 UTCCloudflare Radar scan registered: View Radar report.
Proceso de respuesta ante amenazas Pipeline
Estado de la lista de bloqueados pública
Evasion analysis
Cloaking suspected: scanner and victim titles differ
Stored crawler-versus-browser observations for this host, plus a live fingerprint check for Keitaro-style traffic distribution systems.
- Stored cloaking flag
- Not observed
- Puntuación de encubrimiento
- 0/6
- Last cloaking scan
- Server header seen by scanner
nginx
Scanner note: alive_content: raw=content_403; http=403; via=http_proxy; server=nginx
Tecnologías · 9 identified
Análisis de VirusTotal
Inteligencia comunitaria
1 reporte de la comunidad
CategoríaPHISHING
Detection Summary The Anti-Phishing Volunteers & Associates Security Incident Response System has flagged this as a domain threat, classified as phishing attack against TronLink. Threat detected at 2026-03-01T15:46:47.357Z.
Reportes de la comunidad
Reportado por 1 miembro de la comunidad; visto por primera vez el 13/02/2026
- Reportes almacenados
- 1
- URL únicas reportadas
- 1
Datos y informes externos
¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.