Notification and current-status evidence
The sent-report ledger records the first outgoing report at . A report was sent to the recorded registrar; contact details remain in Domain Intelligence. The latest stored availability evidence still shows the domain reachable; 15 days has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
tronify[.]ltd
“Tronify LTD — TRON Energy for Zero-Fee USDT Transfers”
Observação armazenada
Contraste de títulos observado
Resumo das evidências
Analysis of the domain tronify.ltd, first observed on May 04 2026, indicates that it is being leveraged for a generic phishing campaign. The domain resolves to the IPv4 address 188.114.97.3 and is hosted on infrastructure that uses Cloudflare DNS services, as evidenced by the authoritative nameservers jule.ns.cloudflare.com and sterling.ns.cloudflare.com. Registration was performed through TLD Registrar Solutions Ltd., a registrar that does not inherently imply malicious intent but provides no additional verification of the operator’s identity. The domain has been added to a single external security blocklist and is actively blocked by the PhishDestroy sink‑hole, confirming that at least one downstream security product has identified malicious use.
VirusTotal reports that the domain was examined by 91 antivirus and URL‑reputation engines; none of the scanners returned a malicious verdict at the time of analysis. The absence of detections does not constitute a safety assurance, given the dynamic nature of phishing payloads and the possibility of evasion techniques. No public page title, SSL certificate details, HTTP response codes, or Safe Browsing signals are currently available in the intelligence feed, leaving the surface‑web characteristics of the site unverified. The available evidence suggests that the domain is actively employed in a phishing operation, but the specific lure, targeted brands, and credential‑capture mechanisms remain unknown.
Defenders should continue to monitor DNS queries for 188.114.97.3 and consider network‑level blocks for the address and the domain itself. Inclusion of the domain in internal blocklists, along with the existing PhishDestroy block, will reduce exposure. Ongoing re‑scans with VirusTotal or equivalent sandbox services are recommended to detect any future payload changes.
Instantâneo das evidências enviadas
- Enviado
- Registros do livro-razão
- 1
- ID do caso
PD-20260727-F4A5AD- Artefato PDF
- Evidência em PDF
Base jurídica
Texto completo da evidência
Illegal Activities: Active phishing operation targeting victims
Fraud & Deception: Impersonation of legitimate services
Identity Theft: Collection of credentials under false pretenses
Applicable Laws (Unknown):
International Anti-Cybercrime Regulations
Budapest Convention on Cybercrime
Universal Fraud Prevention Laws
Phishing activities violate international cybercrime conventions and Unknown's domestic fraud laws.
Action Required: This evidence-backed report demonstrates clear violations requiring suspension per your policies. Continued hosting exposes your organization to regulatory scrutiny and potential legal liability.
Data Coverage
Pipeline de resposta a ameaças
Cobertura de listas de bloqueio
10 fontes externas monitoradas · instantâneo de 11/08/2026
10 fontes externas monitoradas Sem correspondência
Linha do tempo de detecção
-
Primeiro registro
Primeiro valor armazenado: Acessível
Denúncias da comunidade
Denunciado por 0 membro da comunidade; visto pela primeira vez em 27/07/2026
- URLs únicas denunciadas
- 1
Inteligência da comunidade
2 denúncias da comunidade
CategoriaPHISHING
Зашел на сайт https://tronify.ltd/, обещали trx , подклчючил trust wallet и с него списали все деньги мгновенно, 12 000 долларов, не ведитесь, полный скам
Captura armazenada
Inteligência de Domínios
Detalhes técnicosDNS, nomes TLS e datas
ICANN OVERSIGHT
Credenciamento e contexto RAA
Credenciamento e contexto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Tecnologias
3 tecnologias identificadas com alta confiança
Análise do VirusTotal
Evidências arquivadas
Análise de desempenho do site
Google PageSpeed Insights — mobile performance audit of tronify.ltd · checked Jul 27, 2026
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo