MALICIOUS — HIGH
troncamp[.]net
The domain troncamp.net is linked to generic phishing and flagged by 3 of 95 VirusTotal vendors, with one security blocklist entry, indicating potential risk.
- VirusTotal
- 3/93
- Blocklists
- No stored match
- Доступність
- Контент недоступний · HTTP 502
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
troncamp.net — Контент недоступний (HTTP 502). Уособлення бренду: Bitget; Тип шахрайства: Crypto Scam. Зведення доказів: VirusTotal 3/93 (Fortinet, Gridinsoft, SOCRadar); URLQuery 1 alert; Spamhaus DBL_PHISH; PhishDestroy score 65/100. Реєстратор: NiceNIC.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
Evidence Analysis
The website troncamp.net operated as a fraudulent decentralized exchange site, presenting itself as "TronCamp • Decentralized Exchange on TRON." This site was classified as a crypto scam, posing the threat of financial theft by deceiving users into connecting wallets or sending cryptocurrency to the attacker under the guise of a legitimate exchange.
Technical evidence indicates the site was detected as malicious by 3 out of 95 VirusTotal vendors, specifically flagged by Fortinet, Gridinsoft, and SOCRadar. It was listed on 1 blocklist. The domain was registered through NiceNIC International Group Co., Limited, with a creation date of 2026-02-21. The site resolved to IP address 188.114.97.3, hosted in the United States by AS13395 Cloudflare, Inc., and used nameservers carioca.ns.cloudflare.com and elias.ns.cloudflare.com. No SSL certificate was present.
As of the time of analysis, the site was offline/down. The risk level is high, as the domain was recently created and flagged by multiple security vendors, indicating an active threat designed to steal cryptocurrency from users.
Обсяг даних12 recorded checks
Розвіддані з мережевої безпеки Registrar context
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | orangerosehamburg.com |
malicious | Sinkholed |
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Збережений знімок
Аналітика доменів
Технічні деталіDNS, SAN-адреси SSL, мітки часу
ICANN OVERSIGHT
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Latest Classified Outcome 2026-08-09 04:28:15 UTC
Аналіз VirusTotal
Архівні докази
Докази та зовнішні звітиIndependent lookups and source reports
PD-20260216-1CFBAA Recipient: abuse@nicenic.net, abuse@verisign-grs.com, compliance@icann.org Victim safety and official reportingImmediate actions and verified reporting channels
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.