buyusdt[.]online
“For Sale Page”
The domain buyusdt.online is currently active and has been identified as a potential threat through multiple security assessments, marking it as a site involved in generic phishing activities. Despite not impersonating any specific brand or utilizing a known drainer kit, the domain poses a significant risk, with an elevated risk level and a low trust score from Scamadviser. Users are advised to exercise caution when interacting with buyusdt.online to avoid falling victim to a phishing or scam attempt.
buyusdt.online has been flagged by 3 of 95 vendors on VirusTotal, including alphaMountain.ai, SOCRadar, and Webroot. The domain is registered through Spaceship, Inc. and was created on November 06, 2025. It resolves to the IP address 44.232.173.249, which is located in the US and is associated with AS16509 Amazon.com, Inc. The site appears on 2 security blocklists, PhishDestroy and ScamSniffer, and is secured by a Let's Encrypt R13 SSL certificate. The page title observed is 'For Sale Page', and the HTTP status is 403, indicating that access to the site is forbidden.
To protect against potential phishing or scam activities on buyusdt.online, users should refrain from providing any personal or financial information on the site. If a user suspects they have interacted with a phishing page, they should change their passwords, enable two-factor authentication (2FA), and monitor their accounts for any signs of unauthorized activity. Additionally, users can report the site to their web browser's built-in reporting tools, as well as to organizations such as PhishTank and the Anti-Phishing Working Group (APWG).
Security Signals
Threat Response Pipeline
Public Blocklist Status
Stored Capture
Domain Intelligence
Technical detailsDNS, SSL SANs, timestamps
ICANN OVERSIGHT
Accreditation and RAA context
Accreditation and RAA context
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Technologies · 4 identified
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Tag management system for deploying marketing and analytics tags.
tagmanager.google.comWeb infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
VirusTotal Analysis
Archived Evidence
Evidence & External Reports
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive