Potentially Malicious Activity
com-trxb.cyou
"The site impersonates ExpressToll, displaying a payment page for an unsettled toll charge on mobile devices while blocking desktop access with a Cloudflare error, indicating cloaking behavior. This, combined with the domain being newly registered and using a high-risk TLD, is consistent with a phishing attack designed to steal financial information."
Note: This finding is based on scans of specific URLs on the domain, not necessarily the root domain itself.
URLert analyzed recent scan activity for com-trxb.cyou and found 1 result.
| Status | Target URL | Time |
|---|---|---|
| Malicious | https://expresstoll.com-trxb.cyou/us | 1d ago |
Run a real-time investigation to understand the specific threats on any URL from this domain.
This assessment is based on automated analysis and may not be definitive.
Always verify independently before taking action.