# usd2c.cyou — SUSPICIOUS > Check usd2c.cyou for potential phishing threats. Domain flagged for suspicious activity; investigation ongoing to ensure user safety. ## Summary PhishDestroy identifies usd2c.cyou as a domain potentially involved in generic phishing activities. Its recent registration and suspicious context warrant caution despite no direct detections. Registered via Gname.com Pte. Ltd., usd2c.cyou resolves to IP 104.21.5.143. VirusTotal analysis shows zero detections, indicating no immediate vendor flags. However, its very recent creation date of March 05, 2026, raises concerns typical for phishing campaigns. The domain remains active and under investigation. Users are advised to avoid interaction until further evidence clarifies its intent. PhishDestroy continues monitoring for new intelligence and recommends blocking access as a precaution. ## Threat Details - Verdict: SUSPICIOUS - Site status: dead (HTTP 403) - Page title: ETHBT ## Domain Intelligence - Registered: 2026-03-05 13:07:01 - Registrar: Gname.com Pte. Ltd. - Country: SG - IP: 104.21.5.143 - IP Country: US - IP City: San Francisco - IP Org: AS13335 Cloudflare, Inc. - Nameservers: bart.ns.cloudflare.com brit.ns.cloudflare.com - SSL Issuer: none ## Detection Status - VirusTotal: 3 vendors flagged Vendors: ["Google Safebrowsing", "Lionic", "Trustwave"] - Google Safe Browsing: clean - Blocklists: 2 hits Lists: ["PhishDestroy", "MetaMask"] ## Evidence - Screenshot: https://i.ibb.co/KRk3rr8/d92f820743e9.png - Cloudflare Radar: https://radar.cloudflare.com/domains/usd2c.cyou - PhishDestroy: https://phishdestroy.io/domain/usd2c.cyou/ - LLM endpoint: https://phishdestroy.io/domain/usd2c.cyou/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/usd2c.cyou/ Last updated: 2026-03-19