MALICIOUS — HIGH
trxbm[.]org
The domain trxbm.org is a confirmed phishing site engaged in brand impersonation targeting the TRON cryptocurrency platform.
- VirusTotal
- 2/91
- Blocklists
- No stored match
- Доступность
- Контент недоступен · HTTP 502
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
trxbm.org — Контент недоступен (HTTP 502). Олицетворение бренда: Tron; Тип мошенничества: Wallet/seed Phishing. Сводка доказательств: VirusTotal 2/91 (CRDF, Gridinsoft); PhishDestroy score 56/100. Регистратор: Tucows.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
Evidence Analysis
The domain trxbm.org is a confirmed phishing site engaged in brand impersonation targeting the TRON cryptocurrency platform. It presents itself as a legitimate TRX/USDT swap and TRON energy rental service but is designed to steal wallet credentials through wallet-connect phishing. No drainer kit was identified, and the site is currently taken offline, though it remains a documented threat for users who may have interacted with it prior to deactivation.
Technical analysis shows trxbm.org was registered on 2025-12-12 02:27:45 via Tucows Domains Inc. and resolves to IP address 188.114.97.3, hosted on Cloudflare’s network (AS13335). Security vendors flagged the domain with 2 of 95 detections on VirusTotal, including alerts from Gridinsoft (trust score 0/100) and SOCRadar. It appears on one security blocklist (PhishDestroy) but was not flagged by Google Safe Browsing. The site lacks an SSL certificate, and its nameservers are colette.ns.cloudflare.com and ian.ns.cloudflare.com. The observed page title reads 'Swap USDT to TRX instantly and rent TRON energy with ease'.
Users who connected wallets to trxbm.org should immediately revoke all token approvals via a blockchain explorer or wallet security tool and transfer funds to a new, secure wallet. Enable two-factor authentication on all cryptocurrency accounts and monitor transaction history for unauthorized activity. Report the phishing domain to platforms like Google Safe Browsing, PhishTank, or the TRON Foundation’s security team to assist in broader mitigation efforts.
Охват данных12 recorded checks
Процесс реагирования на угрозы
Статус в публичных блок-листах
Сохранённый снимок
Аналитика доменов
Технические сведенияDNS, SAN в протоколе SSL, временные метки
ICANN OVERSIGHT
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Анализ VirusTotal
Доказательства и внешние отчетыIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.