trxnetwork[.]app
Resumo das evidências
This domain, trxnetwork.app, is under active investigation for generic phishing activity. It was registered on May 07, 2026, through Dynadot LLC, and resolves to IP address 172.67.208.226, which is hosted by Cloudflare, Inc. in Canada. The SSL certificate is issued by Google Trust Services, and the domain uses Cloudflare nameservers. The page title is currently 'Just a moment...' and the HTTP status code returned is 502, indicating a gateway error, which may suggest the phishing site is temporarily unavailable or behind a protection layer.
The domain has been flagged by PhishDestroy and appears on one security blocklist. It is also recorded in one threat intelligence pulse on AlienVault OTX. Despite these indicators, VirusTotal shows zero detections out of 95 engines, meaning the domain has not yet been widely recognized as malicious by automated scanners. Gridinsoft gives it a trust score of 0 out of 100, reinforcing the suspicion that this domain is not legitimate. The domain remains active as of the report date.
Uncertainty remains about the exact phishing campaign this domain is associated with. The 502 error and Cloudflare hosting may be part of an attempt to obscure the backend infrastructure or to evade analysis. No brand, kit, or specific phishing type has been confirmed from the available data. The lack of VirusTotal detections does not confirm safety, as many phishing domains evade initial detection.
Defenders should monitor this domain for changes in HTTP status or page content, as a functional phishing page may appear later. Network teams should block outbound traffic to 172.67.208.226 and trxnetwork.app at the proxy or firewall level. Email security filters should quarantine any messages linking to this domain. Re-checking VirusTotal and AlienVault OTX periodically will help track if the domain becomes more widely flagged. Any users who may have interacted with the site should be advised to change credentials and enable multi-factor authentication.
Data Coverage
Pipeline de resposta a ameaças
Cobertura de listas de bloqueio
10 fontes externas monitoradas · instantâneo de 11/08/2026
10 fontes externas monitoradas Sem correspondência
Inteligência de Domínios
Detalhes técnicosDNS, nomes TLS e datas
ICANN OVERSIGHT
Credenciamento e contexto RAA
Credenciamento e contexto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Análise do VirusTotal
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo