Analysis of the domain usdt2apigerador.sbs indicates recent creation on July 28 2026 and immediate deployment of infrastructure commonly associated with phishing campaigns. The registrar listed for the domain is CSL Computer Service Langenbach GmbH d/b/a joker.com, a provider that has been observed in other malicious registrations. Authoritative name servers are chan.ns.cloudflare.com and ryan.ns.cloudflare.com, indicating the domain is hosted behind Cloudflare’s DNS service, a typical choice for threat actors seeking rapid DNS changes and DDoS mitigation. The domain resolves to the IP address 188.114.96.3, which belongs to a hosting range frequently employed by abusive sites; no additional context about the host is currently available. The domain appears on two independent security blocklists, specifically PhishDestroy and SEAL, and has been flagged by these feeds as a phishing resource.
VirusTotal has processed the domain with 91 scanning engines; none of the engines reported a detection at the time of analysis. While the absence of a detection does not constitute a safety assurance, it confirms that the domain has not yet been captured by existing malware signatures. No public Safe Browsing, Open Threat Exchange, SSL certificate, or HTTP response data have been published for this domain, and the page title or any landing‑page content has not been disclosed in the available intelligence. Consequently, the exact impersonated brand or the specific credential‑capture technique employed by the site remain unknown.
Defenders should block any network traffic to 188.114.96.3 and add usdt2apigerador.sbs to URL filtering policies. Continuous monitoring of Cloudflare DNS changes for this domain is advisable, as the attacker may alter the resolved address to evade takedown. Analysts should also watch for future VirusTotal submissions or Safe Browsing reports that could reveal the page content or additional indicators of compromise.