usdt-qr[.]to
“Tether (USDT) QR Code Generator”
usdt-qr.to — المحتوى غير متوفر (HTTP 502). انتحال العلامة التجارية: Ethereum; نوع الاحتيال: Brand Impersonation. ملخص الأدلة: VirusTotal 10/95 (alphaMountain.ai, BitDefender, CRDF, CyRadar, ESET); 3 external blocklist matches (Polkadot, Enkrypt, Codeesura); PhishDestroy score 80/100. مسجّل النطاق: Government of Kingdom ….
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
This domain, usdt-qr.to, operates as a fraudulent cryptocurrency service impersonating Tether (USDT) and Ethereum infrastructure. The site presents itself as a legitimate USDT QR code generator, a common tactic used to deceive users into interacting with malicious smart contracts or disclosing wallet credentials. Analysis indicates the primary threat is a crypto drainer mechanism, where victims unknowingly authorize transactions that siphon funds from their wallets. The domain specifically targets Ethereum users, exploiting the popularity of QR-based transactions in decentralized finance (DeFi) ecosystems. Infrastructure analysis reveals multiple high-confidence indicators of compromise. The domain is flagged by 10 out of 95 security vendors on VirusTotal, including detection for phishing and malicious web content. It was registered on January 8, 2024, through the Government of Kingdom of Tonga registrar, a known jurisdiction for high-risk domains. The site resolves to IP address 45.12.2.86, hosted under AS6698 (Virtual Systems LLC) in Ukraine, and appears on five distinct security blocklists, including PhishDestroy and PhishingDB. Notably, the domain lacks SSL encryption, further increasing exposure to man-in-the-middle attacks during data transmission. Users who visited usdt-qr.to should immediately revoke any wallet permissions granted through the site, as these may enable unauthorized fund transfers. It is critical to audit all recent transactions for anomalies and transfer remaining assets to a new, secure wallet address. Browser data, including cookies and cached credentials, should be cleared to eliminate residual session tokens. Given the domain's active status and high-risk classification, users are advised to monitor their wallets for unusual activity and report the incident to relevant blockchain security platforms for further investigation.
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
تحليل VirusTotal
الأدلة المؤرشفة
الأدلة والتقارير الخارجية
“I was misled into using a fake QR code generator which happens to contain the scam's wallet address: TDDrK1ZL3c1zAajZVwYXbHjPitdMQ7i4oJ. After payment, i realized the recipient address was not correct and i lost that fund to the scammer.”
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب