tronswapster[.]com
“TRONSWAPSTER — Купить TRX за USDT”
संग्रहीत अवलोकन
देखा गया शीर्षक अंतर
साक्ष्य सारांश
Analysis of the domain tronswapster.com shows a recent registration (20 Nov 2025) and immediate deployment of a cryptocurrency‑focused scam infrastructure. The site resolves to the Cloudflare anycast address 198.18.1.99 and uses Cloudflare’s DNS resolvers keaton.ns.cloudflare.com and lina.ns.cloudflare.com. TLS termination is provided by a Google Trust Services / WE1 certificate, and HTTP/3 is advertised, indicating a modern web stack. Current HTTP response code 521 suggests the origin server is unavailable, a pattern often observed when attackers temporarily hide behind Cloudflare to evade takedown.
Public intelligence flags the domain as a cryptocurrency phishing operation. The page title, "TRONSWAPSTER — Купить TRX за USDT," directly advertises the purchase of TRX using USDT, confirming the intent to lure victims into a crypto transaction scam. The domain appears on a single security blocklist maintained by PhishDestroy, and VirusTotal scanning shows two of ninety‑five security vendors flagging it as malicious, reinforcing the suspicion despite a low detection ratio. Registration was performed through Tucows Domains Inc., a common registrar for disposable or fast‑turnaround domains used in illicit campaigns.
Uncertainties remain regarding the underlying payload or credential‑harvesting mechanism, as the content of the webpage has not been captured in this report. No additional indicators such as malicious scripts, redirects, or phishing forms have been observed, limiting attribution to a purely domain‑level assessment. Defenders should proactively block the domain at DNS and proxy layers, monitor outbound connections to the Cloudflare‑owned IP range for anomalous traffic, and correlate any attempted TRX/USDT transfers with user activity logs. Continuous re‑scanning with multi‑vendor engines is advised to capture evolving detection signatures, and any related indicators should be added to internal threat‑intel feeds to mitigate future exploitation.
Data Coverage
धमकी प्रतिक्रिया पाइपलाइन
ब्लॉकलिस्ट कवरेज
10 निगरानी वाले बाहरी स्रोत · संग्रहीत स्नैपशॉट 11/08/2026
पहचान समयरेखा
-
डोमेन स्थिति
पहुँच योग्य → पहुँच योग्य नहीं
-
डोमेन स्थिति
पहुँच योग्य → पहुँच योग्य नहीं
-
Cloudflare Radar
Cloudflare Radar स्कैन संग्रहीत · स्कैन खोलें
-
Cloudflare Radar
Cloudflare Radar स्कैन संग्रहीत · स्कैन खोलें
सहेजा गया कैप्चर
डोमेन इंटेलिजेंस
तकनीकी विवरणDNS, TLS नाम और समय-मुद्राएँ
ICANN OVERSIGHT
प्रत्यायन और आरएए संदर्भ
प्रत्यायन और आरएए संदर्भ
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
वायरसटोटल विश्लेषण
क्या आप इस साइट से प्रभावित हुए?
यदि आपने खाता क्रेडेंशियल, व्यक्तिगत या भुगतान जानकारी दर्ज की है, या इस डोमेन से कोई फ़ाइल डाउनलोड की है, तो तुरंत कार्रवाई करें। घटना की रिपोर्ट करने और अपनी सुरक्षा करने में आपकी सहायता के लिए नीचे संसाधन दिए गए हैं।
अपने स्थानीय अधिकारियों को रिपोर्ट करें
आधिकारिक साइबर अपराध संपर्क, या एक शिकायत ड्राफ्ट बनाएं → प्राप्त करने के लिए अपना देश चुनें।
किसी भी डोमेन की जाँच करें
संग्रहीत ब्लॉकलिस्ट, WHOIS, DNS और सार्वजनिक स्कैन साक्ष्य का उपयोग करके खतरे का विश्लेषण
अभी स्कैन करेंफ़िशिंग की रिपोर्ट करें
संदिग्ध डोमेन हमारे थ्रेट डेटाबेस में जमा करें — समुदाय की सुरक्षा करें
रिपोर्ट करेंसीधा खतरा फीड
हाल की फ़िशिंग रिपोर्टें और उपलब्धता में परिवर्तन देखे गए
निगरानी करेंजानकारी में रहें, सुरक्षित रहें
लाइव खतरों की निगरानी करें या यदि आपको लगता है कि यह एक गलत सकारात्मक है तो इस लिस्टिंग को चुनौती दें।