# PhishDestroy threat dossier — usdtflasher.live.thorchainswap.com ================================================================ Fetched: 2026-05-07 13:32:27 UTC Canonical: https://phishdestroy.io/domain/usdtflasher.live.thorchainswap.com/ ## VERDICT ---------------------------------------------------------------- HIGH THREAT — malicious activity confirmed Composite threat score: 60/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 0/95 security vendors flagged this domain ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 64.20.37.43 (US, Secaucus) ASN: AS19318 Interserver, Inc Hosting org: Interserver, Inc Registrar: Dynadot Inc Nameservers: dns2018a.trouble-free.net, dns2018b.trouble-free.net Registered: 2026-04-12 Page title: usdtflasher.live.thorchainswap.com HTTP response: 200 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / R12 Expires: 2026-08-04 Status: INVALID chain Fingerprint: abc00e8a9a1e24a7ef15e461001b351336b69b2a57ad0d7bba22424a8f30aef9 Subject Alternative Names (related infrastructure — often same operator): - flashflow.club - flashnode.club - flashtrc20.sale - flashtrc20.sale.thorchainswap.com - unitedflash.vip - unitedflash.vip.thorchainswap.com - usdtflasher.live - www.flashflow.club.thorchainswap.com - www.flashnode.club.thorchainswap.com - www.flashtrc20.sale.thorchainswap.com - www.unitedflash.vip.thorchainswap.com - www.usdtflasher.live.thorchainswap.com ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-04-12 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-05-07 09:42:15 UTC (by PhishDestroy tracker) Last verified: 2026-05-07 14:00:40 UTC Current status: ACTIVE / observable ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019e012a-49c5-756c-b69a-2a211b4e29b3/ Wayback Machine: https://web.archive.org/web/*/usdtflasher.live.thorchainswap.com crt.sh CT logs: https://crt.sh/?q=%25.usdtflasher.live.thorchainswap.com Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=usdtflasher.live.thorchainswap.com AlienVault OTX: https://otx.alienvault.com/indicator/domain/usdtflasher.live.thorchainswap.com URLhaus: https://urlhaus.abuse.ch/host/usdtflasher.live.thorchainswap.com/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-05-07 09:44:23 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] PhishDestroy identifies usdtflasher.live.thorchainswap.com as an active fake-Tether “USDT flash” scam page designed to trick cryptocurrency users into sending USDT for promised instant returns. The domain resolves to IP 64.20.37.43, was registered on April 12, 2026 through Dynadot Inc, and currently carries a Let’s Encrypt SSL certificate. VirusTotal scanning as of today shows zero detections out of 95 engines, indicating it is not yet widely blocked by antivirus or browser defenses. This domain poses a specific high-risk threat: it masquerades as a legitimate “USDT flasher” or “USDT flash service,” a term used in underground forums to describe fraudulent tools that claim to generate free or instant USDT transfers. The subdomain path “live.thorchainswap.com” is abused to lend false credibility by borrowing the name of a known swap interface. Attackers typically promote such pages via social media ads or private chats, luring victims with messages like “Click to double your USDT instantly.” Once a user connects a wallet or enters private keys or seed phrases, the page either drains funds directly or harvests credentials for later theft. The domain’s recent creation date (April 12, 2026) and low VirusTotal score suggest a fast-moving campaign that has evaded most automated detection layers. Users who visited usdtflasher.live.thorchainswap.com should immediately disconnect any connected wallets, revoke any permissions granted, and move remaining assets to a new wallet with a unique seed phrase. Do not enter private keys, seed phrases, or passwords on this site. Report the domain to your wallet provider, browser, and platforms like PhishDestroy, Google Safe Browsing, and VirusTotal. Consider enabling hardware wallet signing for future transactions to reduce exposure to fake web interfaces. Stay vigilant: any site promising “instant USDT” or “free flash” is almost certainly a scam. ## EVIDENCE HASHES ---------------------------------------------------------------- TLS cert SHA-256: abc00e8a9a1e24a7ef15e461001b351336b69b2a57ad0d7bba22424a8f30aef9 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (volunteer takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/usdtflasher.live.thorchainswap.com/ JSON API: https://api.destroy.tools/v1/check?domain=usdtflasher.live.thorchainswap.com Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: volunteer-driven open-source threat-intelligence platform. Tracked: 146,920 domains (52,558 alive under monitoring, 94,028 confirmed takedowns/dead). Site: https://phishdestroy.io