Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is registry@key-systems.net.
The latest stored availability evidence still shows the domain reachable; 6 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
trxuk[.]org
Проверка домена trxuk.org на фишинг и безопасность
“Conversion USDT ⇄ TRX et achat d’énergie TRON | Rapide, sûr et fiable”
trxuk.org — Ошибка сервера (HTTP 502). Олицетворение бренда: Telegram; Тип мошенничества: Crypto Scam. Сводка доказательств: VirusTotal 2/91 (CRDF, Gridinsoft); 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 66/100. Регистратор: Internet Domain Servic….
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
Analysis of trxuk.org indicates a newly registered domain (created 21 Feb 2026) that was used to host a crypto‑focused impersonation of the Telegram brand. The authoritative nameservers maleah.ns.cloudflare.com and miles.ns.cloudflare.com resolve the domain to 172.67.148.204, an address owned by Cloudflare (AS13335) located in the United States. No TLS certificate was presented, confirming the absence of HTTPS protection at the time of capture. The page title “Conversion USDT ⇄ TRX et achat d’énergie TRON | Rapide, sûr et fiable” aligns with the declared crypto‑scam classification and brand‑targeting of Telegram.
Reputation services rated the site at the lowest possible Gridinsoft trust score (0/100). The domain appears on three independent security blocklists and was actively blocked by PhishDestroy, MetaMask, and SEAL. VirusTotal recorded two positive detections out of ninety‑five scanners, reinforcing the malicious assessment. The registrar listed is Internet Domain Service BS Corp., and the site’s current HTTP status is offline, suggesting the operators have taken the payload down or are rotating infrastructure.
Uncertainty remains regarding the exact phishing kit or any persistence mechanisms, as no further forensic artifacts were captured. Defenders should continue to deny connections to the resolved IP address, add the domain and its IP to local blocklists, and monitor for new registrations at the same registrar or with similar naming patterns. Because the hosting provider is Cloudflare, broader network‑level filtering of the AS13335 range should be considered only if collateral impact is acceptable. Ongoing threat‑intel feeds should be queried for re‑use of the same nameservers or page titles, and any future DNS queries for trxuk.org must be flagged for manual review.
Процесс реагирования на угрозы
Статус в публичных блок-листах
Сохранённый снимок
Аналитика доменов
Технические сведенияDNS, SAN в протоколе SSL, временные метки
ICANN OVERSIGHT
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Анализ VirusTotal
Доказательства и внешние отчеты
PD-20260203-2E7EFA Recipient: registry@key-systems.net Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание