coin-qrs[.]to
“Bitcoin QR Code Generator Online”
coin-qrs.to — المحتوى غير متوفر. انتحال العلامة التجارية: Ethereum; نوع الاحتيال: Crypto Scam. ملخص الأدلة: VirusTotal 12/95 (ADMINUSLabs, alphaMountain.ai, CyRadar, ESET, Emsisoft); PhishDestroy score 91/100. مسجّل النطاق: Government of Kingdom ….
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
The domain coin-qrs.to has been identified as a confirmed brand impersonation threat specifically targeting Ethereum users. This phishing site is currently offline, having been taken down after security researchers flagged its malicious intent. The domain was registered through the Government of Kingdom of Tonga on April 27, 2024, and was assigned the IP address 45.12.2.86. Despite its page title claiming to be a "Bitcoin QR Code Generator Online," the site was actually designed to impersonate Ethereum, likely to steal cryptocurrency credentials or deploy a crypto drainer.
Technical analysis reveals significant red flags. The domain was flagged by 12 out of 95 security vendors on VirusTotal, indicating a high level of malicious detection. It also appears on one security blocklist. The SSL certificate was issued by Let's Encrypt (R13), which is commonly abused by phishing sites due to its free and automated issuance. The domain's recent creation date and the use of a Tongan registrar further suggest intentional obfuscation by threat actors. PhishDestroy's investigation confirms that this site posed a direct risk to Ethereum users, as it attempted to harvest sensitive information through deceptive branding.
Given that coin-qrs.to is now offline, the immediate threat has been mitigated. However, users should remain vigilant as similar domains may appear under different names. PhishDestroy recommends that anyone who interacted with this site—especially by entering credentials or connecting a wallet—should take immediate action: change passwords, revoke wallet permissions, and monitor accounts for unauthorized activity. To stay safe, always verify domain authenticity by cross-referencing with trusted sources like PhishDestroy before engaging with cryptocurrency-related sites.
مؤشرات الأمان
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
التقنيات · 7 identified
High-performance HTTP server and reverse proxy, known for stability and low resource usage.
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comFast, small JavaScript library simplifying HTML manipulation, event handling, and Ajax.
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Web analytics service tracking website traffic and user behavior.
marketingplatform.google.comتحليل VirusTotal
الأدلة المؤرشفة
تحليل أداء الموقع
Google PageSpeed Insights — mobile performance audit of coin-qrs.to · checked Mar 2, 2026
الأدلة والتقارير الخارجية
“@drainer Telegram”
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب