gettrxs[.]org
“walletauthorizer”
Resumo das evidências
PhishDestroy identifies gettrxs.org as a Bitcoin wallet drainers phishing site, currently under active investigation as of seed 8d2177. The domain poses a significant risk to crypto investors by masquerading as a legitimate transaction service while embedding malicious drainer scripts designed to empty Bitcoin wallets. No specific brand impersonation or known drainer kit (e.g., Angel Drainer, Inferno Drainer) has been publicly attributed to this domain yet, but its phrasing and infrastructure suggest a targeted campaign against digital asset holders.
This domain exhibits several concerning technical indicators: it resolves to IP 69.62.87.32, is registered through NAMECHEAP INC, and was created on April 13, 2026. VirusTotal currently flags it at 1/95 detections, indicating it remains undetected by most antivirus engines. The SSL certificate is issued by Let's Encrypt, which does not inherently indicate malicious intent but reflects a common tactic among phishing domains to appear legitimate. This domain has not yet been added to Google Safe Browsing (GSB) lists or major blocklists, leaving users exposed without prior warnings.
While flagged as under investigation, this domain represents an active and evolving threat. Response actions include domain takedown requests submitted to NAMECHEAP and IP-based blocking at the network perimeter. However, the absence of detections and blocklist entries suggests a high-risk window where users may unknowingly interact with the site. Remaining risk includes potential expansion of the drainer campaign, integration with bulletproof hosting, or rapid domain rotation to evade detection. Immediate mitigation includes user education against unsolicited transaction links, wallet address verification, and enterprise-level DNS/URL filtering with real-time threat intelligence feeds.
Instantâneo das evidências enviadas
- Enviado
- Registros do livro-razão
- 1
- ID do caso
PD-20260413-0A5E39- Título da página capturada
- walletauthorizer
- Artefato PDF
- Evidência em PDF
Base jurídica
Texto completo da evidência
Policy Violations: Domain Registration Agreement prohibits hacking, misuse of domain to conduct attacks, scam and fraudulent activities; AUP allows immediate suspension
Applicable Laws: CFAA 18 U.S.C. §1030, Wire Fraud 18 U.S.C. §1343, CAN-SPAM Act
Data Coverage
Pipeline de resposta a ameaças
Cobertura de listas de bloqueio
10 fontes externas monitoradas · instantâneo de 12/08/2026
Captura armazenada
Inteligência de Domínios
Detalhes técnicosDNS, nomes TLS e datas
ICANN OVERSIGHT
Credenciamento e contexto RAA
Credenciamento e contexto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Análise do VirusTotal
Análise de desempenho do site
Google PageSpeed Insights — mobile performance audit of gettrxs.org · checked Apr 13, 2026
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo