| Domain | Purpose | Severity | Status (verified 2026-09-20) |
|---|---|---|---|
| tronify.rent | Primary attack website (impersonates the real "Tronify" TRON energy-rental brand) | CRITICAL | Active โ resolves to 185.178.208.133, fronted by DDoS-Guard, homepage last modified 2026-09-14 |
| lending.fhogu.pw | Payload host (greenbid.js drainer) + C&C backend | CRITICAL | Active โ resolves via Cloudflare anycast (104.21.94.164 / 172.67.138.20), payload last modified 2026-08-30, /tron/config actively serving live attacker addresses |
Note the two tiers of infrastructure use two different reverse-proxy providers โ DDoS-Guard for the phishing frontend, Cloudflare for the payload/C&C host โ which obscures both true origin servers and means a single provider takedown request won't remove both.
All 12 endpoints below were extracted directly from the live payload on 2026-09-20 (regex search for /tron/[a-zA-Z0-9_/-]+ against the downloaded file, preserved at evidence/payload/greenbid.js):
An earlier draft of this list had 8 entries; direct extraction found 4 more (/tron/balances/, /tron/client-log, /tron/funding/status/, /tron/walletconnect).
| Attribute | Value | Severity |
|---|---|---|
| Filename | greenbid.js | CRITICAL |
| Size | 150,274 bytes | HIGH |
| SHA-256 | 0f6d64472d6369a098f403db117b1285e79b0fdac79caaa639fc0e50e5bf4416 | CRITICAL |
| File Type | JavaScript (text/javascript), served via Cloudflare | Info |
| Location | https://lending.fhogu.pw/greenbid.js?v=1 | CRITICAL |
The SHA-256 hash is the single most reliable file IoC here โ unlike string signatures, it can't be evaded by attacker string obfuscation, but it also breaks the instant the attacker changes even one byte of the file. Use both.
Unique strings found in greenbid.js payload:
When greenbid.js executes, it logs debug messages to browser console:
Drainer stores visitor ID in localStorage:
The attacker's destination addresses are not hardcoded in greenbid.js โ they're loaded dynamically from /tron/config. That endpoint is live and unauthenticated, so we queried it directly on 2026-09-20 and got real values, then verified them on-chain via TronGrid/TronScan (raw responses in evidence/onchain/).
| Address Type | Address (as of 2026-09-20 โ will rotate) | On-chain status |
|---|---|---|
Token Spender (config.tronSpender) |
TV6n8cCLmX5mRCMMNvcE1K1i87Yo9Ys5rv |
Created 2026-07-23; last active 2026-09-19; currently holds 14,635.00 USDT + 875.44 TRX |
TRX/Token Sweep Destination (config.tronSweepAddress) |
TLv3iSnZxWghEmadLDzuAK2p5GkAwg7tpJ |
Created 2026-07-23 (39s after the spender address); currently holds 32,288.30 USDT + 3,213.53 TRX; received USDT from ~25 distinct addresses in the last 30 transfers (2026-08-27 to 2026-09-19) |
Exchange contract (config.tronExchangeContract) |
TDE7vfjJuYqEzzKw6hfdSB3dfLQyXDYPux |
Deployed smart contract (not an EOA); on-chain account_name decodes to "TronEnergy" |
| Observed consolidation targets (funds moved from the sweep address) | TVkRFwgyvUrJqGe3xZaZvTj4vxM5bzherw (received 24,000 USDT, 2026-08-19)TZ2PfDN5wNcsrabcB2JoMagx8vY7VEmQqX (received 6,000 USDT, 2026-08-16) |
Not yet traced further โ good next pivot points for law enforcement / chain analysts, since they represent where funds go after theft rather than the (more easily rotated) collection point |
Caveat: because the C&C config is fetched fresh on every visit, the attacker can change these addresses at any time without redeploying greenbid.js. Treat the specific addresses above as a dated snapshot for pivoting/tracing, not a permanent blocklist entry โ re-query /tron/config periodically if operationalizing this.
Blockchain observation patterns for exploit detection:
Without known attacker addresses, look for exploitation patterns:
Users who visit tronify.rent exhibit predictable behavior patterns:
Victims post on public channels after exploitation:
| Date | Event | Evidence | Confidence |
|---|---|---|---|
| 2026-07-23 | Attacker's spender and sweep addresses created (39 seconds apart) | TronGrid create_time field on both addresses (evidence/onchain/) |
Confirmed (on-chain) |
| 2026-08-16 to 2026-09-19 | Active theft window observed in most recent transaction page | ~25 distinct USDT senders into the sweep address; two consolidation transfers out (evidence/onchain/trc20_transfers_tronSweepAddress_page1.json) | Confirmed (on-chain) |
| 2026-08-30 | Payload last modified | Last-Modified HTTP header on greenbid.js (evidence/payload/) |
Confirmed (HTTP header) |
| 2026-09-14 | tronify.rent homepage last modified | Last-Modified HTTP header on the site (evidence/site/) |
Confirmed (HTTP header) |
| 2026-09-19 22:12 | Spender address's most recent on-chain activity | TronGrid latest_opration_time |
Confirmed (on-chain) |
| 2026-09-20 | This verification pass: live payload, C&C config, and on-chain data all pulled directly | All files in evidence/, checksummed in evidence/SHA256SUMS.txt |
Confirmed (direct collection) |
| ~2026-06 (unverified) | A YouTube video titled around "Tronify.rent Review" exists | Found via web search; we did not verify the video's upload date, view count, or that its content specifically calls the site a scam | Unverified โ do not cite as campaign-launch evidence |
Correction: an earlier draft of this document asserted that tronify.app, tronify.llc, tronrental.com, and tronified.com were confirmed-legitimate alternatives, without checking them. We checked. Results below are from direct DNS resolution and HTTP requests on 2026-09-20 (raw output in evidence/dns/resolution_snapshot.txt and evidence/site_legit/) โ do not point users at any of these as a "safe alternative" without re-verifying first, since domain status changes and an expired domain can be re-registered by anyone, including a threat actor:
| Domain | Live status (checked 2026-09-20) | Note |
|---|---|---|
| tronify.app | No DNS record (does not currently resolve) | Appeared in search results as "TRONIFY โ Rent TRON Energy," but is not live now |
| tronify.llc | No DNS record | Not currently live |
| tronified.com | No DNS record | Not currently live |
| tronify.pro | Resolves, but 302-redirects to google.com | Dead/abandoned, not offering any service |
| tronify.io / tronify.ai | Live, resolving, serving a real single-page app (Chinese-language TRON energy/bandwidth rental + TRX staking product) | The only Tronify-branded domain in this set we found to be genuinely live and serving a product as of this check |
Why this matters more than a typosquat table: a third-party crypto news article reports that Trust Wallet integrated a service called "Tronify" for automatic energy rental โ meaning the brand "Tronify" carries real, independently-earned trust in this space. tronify.rent is not a misspelling of one specific competitor; it's occupying the same brand name under a different, unusual TLD (.rent) in a space where several legitimate-sounding "Tronify" domains are already dead or abandoned. A user who searches "is Tronify legit" will find genuinely positive results that say nothing about which TLD they apply to. We could not confirm whether the "Tronify Energy Solutions LLC, EIN 87-2945163" registration displayed on tronify.rent belongs to a real filed entity, was copied from a real one, or was invented โ none of the other Tronify-branded sites we checked displayed that specific EIN for comparison, so this remains an open question rather than a settled one.