usdgateway[.]me
“$USDT Airdrop”
Resumen de las pruebas
Analysis of the domain usdgateway.me indicates it was actively involved in a cryptocurrency scam targeting users with a fraudulent USDT airdrop offer. The domain, registered on February 21, 2026, through HOSTINGER operations, UAB, was flagged by multiple security vendors and blocklists, including PhishDestroy and ScamSniffer, which classified it as a crypto scam. Infrastructure analysis reveals the domain resolved to IP address 188.114.97.3, hosted on Cloudflare's network (AS13335) in the United States. The absence of an SSL certificate further undermines its legitimacy, as secure connections are a baseline expectation for financial or crypto-related services.
The page title, $USDT Airdrop, directly aligns with the identified scam type, suggesting the domain was designed to deceive users into believing they were participating in a legitimate cryptocurrency giveaway. Eight of ninety-three security vendors on VirusTotal flagged the domain, reinforcing its malicious classification. Gridinsoft assigned a trust score of 0/100, indicating a complete lack of credibility. The domain's nameservers, sullivan.ns.cloudflare.com and ulla.ns.cloudflare.com, are consistent with Cloudflare's infrastructure, though this alone does not mitigate the threat.
As of July 24, 2026, usdgateway.me is offline, but defenders should remain vigilant. Historical DNS and WHOIS records should be preserved for forensic analysis, and any associated IP addresses or domains should be monitored for resurgence. Organizations are advised to block the domain and its resolving IP at the network level, update endpoint protection rules, and alert users to the risks of crypto airdrop scams. The exact mechanics of the scam—such as whether it involved wallet drainers or credential harvesting—are not confirmed in the available data, but the presence of a phishing kit labeled 'Airdrop Scam' suggests a structured approach to deception.
Data Coverage
Proceso de respuesta ante amenazas Pipeline
Cobertura de listas de bloqueo
10 fuentes externas supervisadas · instantánea del 11/08/2026
9 fuentes externas supervisadas Sin coincidencias
Cronología de detección
-
Cloudflare Radar
Análisis de Cloudflare Radar almacenado · Abrir análisis
Inteligencia forense
Análisis de VirusTotal
¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.