tron[.]gd
Analyse phishing et sécurité de tron.gd
“TRON.GD”
tron.gd — Contenu indisponible (HTTP 502). Usurpation de l'identité de la marque : Binance; Type d'arnaque : Crypto Scam. Résumé des preuves: VirusTotal 12/91 (alphaMountain.ai, BitDefender, Chong Lua Dao, CRDF, ESET); PhishDestroy score 91/100. Bureau d’enregistrement: Gname.
L’analyse détaillée de PhishDestroy AI reste en anglais afin de préserver le relevé forensique original.
Evidence Analysis
Analysis of the domain tron.gd shows a newly registered site created on February 21, 2026 that is currently offline but exhibits several high‑confidence indicators of a crypto‑related impersonation campaign targeting Binance users. The domain resolves to IP address 188.114.97.3, which is owned by Cloudflare, Inc. (AS13335) and geolocated to the United States. No SSL certificate is present, meaning the site does not serve traffic over HTTPS. The authoritative nameservers are fattouche.ns.cloudflare.com and gail.ns.cloudflare.com, both belonging to Cloudflare’s DNS infrastructure.
The registrar listed is Gname.com Pte. Ltd. A single security blocklist has already flagged the domain, and PhishDestroy has explicitly blocked it. VirusTotal reports that ten of ninety‑three scanning engines have marked the domain as malicious, reinforcing the suspicion of a malicious payload or credential‑harvesting activity. Gridinsoft assigns a trust score of 1 out of 100, indicating an extremely low reputation. The page title returned from the host is simply "TRON.GD," and the listed scam type is "Crypto Scam," confirming the intent to deceive users in a cryptocurrency context.
While the site is offline at the time of this report, the infrastructure—particularly the Cloudflare‑hosted IP and the registrar—could be reused for future campaigns. Defenders should add tron.gd to URL filtering and DNS blocklists, monitor the associated IP address for any unexpected activation, and watch for other domains registered through Gname.com that resolve to the same Cloudflare nameservers. Continuous threat‑intel feeds should be consulted for any emergence of similar Binance‑impersonation domains, and any internal alerts triggered by traffic to the IP or domain should be investigated promptly.
Couverture des données13 recorded checks
Signaux de sécurité
Processus de réponse aux menaces Pipeline
Statut de la liste de blocage publique
Analyse VirusTotal
Preuves archivées
Données factuelles et rapports externesIndependent lookups and source reports
PD-20260107-F89FBE Recipient: complaint@gname.com Victim safety and official reportingImmediate actions and verified reporting channels
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.