Notification and current-status evidence
The sent-report ledger records the first outgoing report at . A report was sent to the recorded registrar; contact details remain in Domain Intelligence. The latest stored availability evidence still shows the domain reachable; 3 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
trxinfo[.]shop
“USDT to TRX Conversion & TRON Energy Purchase | Fast, Secure, Reliable”
Kaydedilmiş gözlem
Gözlemlenen başlık farkı
Kanıt özeti
PhishDestroy identifies trxinfo.shop as an active crypto drainer scam deployed to steal cryptocurrency assets from unsuspecting users. This domain leverages deceptive tactics to trick victims into connecting wallets or authorizing fraudulent transactions, resulting in irreversible fund loss. The threat remains unflagged on VirusTotal despite clear malicious intent, underscoring the need for proactive detection and sharing of threat intelligence within the security community.
This domain, trxinfo.shop, exhibits multiple red flags across key threat intelligence sources. VirusTotal currently reports 1 out of 95 antivirus engines detecting the threat, indicating a critical gap in signature-based detection. The domain resolves to IP 82.112.239.11, which is associated with hostile infrastructure hosting multiple phishing campaigns. The SSL certificate is issued by Let’s Encrypt, a trusted provider often abused by malicious actors to lend false legitimacy to fraudulent sites. The domain uses a recently registered top-level domain (.shop), though exact creation date is pending further registry analysis. It has not yet been listed on major public blocklists such as PhishTank or OpenPhish, increasing the risk of unchecked victim exposure.
To mitigate exposure to this crypto drainer scam, users should immediately block trxinfo.shop at the network and DNS levels. Avoid clicking any links or connecting cryptocurrency wallets to this domain. Enable wallet transaction simulation tools or use hardware wallets with screen protection to prevent unauthorized approvals. Organizations are advised to deploy DNS filtering rules and integrate threat intelligence feeds that include real-time domain reputation checks. Sharing this IOC (trxinfo.shop, 82.112.239.11) across threat-sharing platforms will help raise collective detection rates and protect the broader ecosystem from cryptocurrency theft.
Gönderilen kanıt anlık görüntüsü
- Gönderildi
- Kayıt defteri kayıtları
- 1
- Vaka kimliği
PD-20260415-DF416E- Yakalanan sayfa başlığı
- USDT to TRX Conversion & TRON Energy Purchase | Fast, Secure, Reliable
Kanıtın tam metni
Policy Violations: AUP prohibits illegal activity including fraud, phishing, malware hosting; Hostinger may suspend/terminate services and domains
Applicable Laws: Lithuanian Criminal Code (Ch. XXX, §§196–198 data/system crimes; §§214–215 electronic fraud); EU Directive 2013/40/EU
Data Coverage
Tehdit Müdahale Pipeline
Engelleme listesi kapsamı
10 izlenen harici kaynak · kayıtlı anlık görüntü 11.08.2026
Kaydedilen görüntü
Etki Alanı Analizi
Teknik ayrıntılarDNS, TLS adları ve zaman damgaları
ICANN OVERSIGHT
Akreditasyon ve RAA bağlamı
Akreditasyon ve RAA bağlamı
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
VirusTotal Analizi
Site Performans Analizi
Google PageSpeed Insights — mobile performance audit of trxinfo.shop · checked Apr 15, 2026
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin