# PhishDestroy threat dossier — usdtlengqanbaoapp.com.cn ================================================================ Fetched: 2026-05-07 10:30:52 UTC Canonical: https://phishdestroy.io/domain/usdtlengqanbaoapp.com.cn/ ## VERDICT ---------------------------------------------------------------- SUSPICIOUS — under active investigation Composite threat score: 35/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 0/95 security vendors flagged this domain ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 186.241.202.81 Registrar: 北京新网数码信息技术有限公司 Nameservers: alberto.ns.cloudflare.com, malavika.ns.cloudflare.com Registered: 2026-04-20 Page title: USDT冷钱包App下载 | 安全离线存储泰达币钱包应用 HTTP response: 200 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / R13 Expires: 2026-07-20 Status: INVALID chain Fingerprint: 04a35bb966637f88c5bce3968de0aeaa52a59cb774fcff8da1de7fd170c1a4da ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-04-20 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-05-07 09:40:10 UTC (by PhishDestroy tracker) First reported: 2026-05-07 06:41:21 UTC (abuse notice filed) Last verified: 2026-05-07 13:20:41 UTC Current status: ACTIVE / observable ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019e0128-b176-7607-a832-6766783d3f3d/ Wayback Machine: https://web.archive.org/web/*/usdtlengqanbaoapp.com.cn crt.sh CT logs: https://crt.sh/?q=%25.usdtlengqanbaoapp.com.cn Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=usdtlengqanbaoapp.com.cn AlienVault OTX: https://otx.alienvault.com/indicator/domain/usdtlengqanbaoapp.com.cn URLhaus: https://urlhaus.abuse.ch/host/usdtlengqanbaoapp.com.cn/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-05-07 09:41:36 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] PhishDestroy identifies usdtlengqanbaoapp.com.cn as a generic phishing domain impersonating a USDT wallet service, actively hosted on 186.241.202.81. This domain was flagged due to its suspicious alignment with cryptocurrency wallet branding, specifically targeting users of Tether (USDT) transactions. No known drainer kit has been publicly linked to this domain, but its recent creation and low detection rate suggest it may be part of an emerging campaign leveraging brand impersonation to harvest credentials or crypto wallet access. This domain was registered through 北京新网数码信息技术有限公司 on April 20, 2026, and resolves to IP 186.241.202.81 via a Let’s Encrypt SSL certificate. VirusTotal shows 0/95 detections (seed 088133) and no Google Safe Browsing (GSB) flagging, indicating it remains under the radar. With no current blocklist entries, this domain poses an elevated risk for users seeking legitimate USDT services. The domain is currently active and under investigation, with no active takedown or mitigation measures in place. Users should avoid interacting with usdtlengqanbaoapp.com.cn and report it to their security teams. Remaining risk includes continued phishing operations due to low detection and lack of proactive blocking. Security teams are advised to monitor for emerging campaigns and update blocklists accordingly. ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260507-1B47E4 TLS cert SHA-256: 04a35bb966637f88c5bce3968de0aeaa52a59cb774fcff8da1de7fd170c1a4da ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (volunteer takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/usdtlengqanbaoapp.com.cn/ JSON API: https://api.destroy.tools/v1/check?domain=usdtlengqanbaoapp.com.cn Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: volunteer-driven open-source threat-intelligence platform. Tracked: 146,804 domains (58,455 alive under monitoring, 88,088 confirmed takedowns/dead). Site: https://phishdestroy.io