usdt-mix[.]top
“Best USDT Mixer 2025 - USDT ERC20 and TRC20 Mixing Service”
usdt-mix.top — error del servidor (HTTP 502). Suplantación de marca: Ethereum; Tipo de estafa: Crypto Scam. Resumen de las pruebas: VirusTotal 5/95 (alphaMountain.ai, CyRadar, Forcepoint ThreatSeeker, Lionic, Webroot); PhishDestroy score 65/100. Registrador: NiceNIC.
El análisis detallado de PhishDestroy AI se mantiene en inglés para conservar el registro forense original.
The domain usdt-mix.top has been identified as a brand impersonation threat, specifically targeting the Ethereum brand. This site presents itself as a USDT mixing service, promising to mix ERC20 and TRC20 tokens, but is in fact a phishing operation designed to steal cryptocurrency from unwary users. The page title 'Best USDT Mixer 2025 - USDT ERC20 and TRC20 Mixing Service' is a lure to attract victims seeking privacy-enhancing services. PhishDestroy confirms this domain is part of a known threat pattern where attackers impersonate legitimate cryptocurrency platforms to harvest credentials or funds.
Technical analysis reveals that usdt-mix.top resolves to IP address 188.114.96.3 and uses an SSL certificate issued by Google Trust Services under the identifier WE1. The domain was registered through NiceNIC International Group Co., Limited, a registrar often associated with high-risk domains. VirusTotal data shows 5 out of 95 security vendors flag this domain as malicious, and it appears on 1 security blocklist. AlienVault OTX records indicate it was found in 1 threat intelligence pulse. The domain was created on May 29, 2025, indicating a very recent setup, which is typical for short-lived phishing campaigns.
As of the latest check, usdt-mix.top is offline, suggesting that the hosting provider or authorities have taken action to disable the site. However, the risk remains elevated because the attackers may launch similar domains under new names. Users are strongly advised to avoid visiting this domain and to never enter personal information, wallet credentials, or send cryptocurrency to any address linked to it. If users have interacted with this site, they should immediately change passwords, enable two-factor authentication, and monitor their accounts for unauthorized transactions. PhishDestroy recommends using reputable security tools to block such threats and staying vigilant against deceptive cryptocurrency services.
Inteligencia de seguridad de red Registrar context
Proceso de respuesta ante amenazas Pipeline
Estado de la lista de bloqueados pública
Captura guardada
Inteligencia de dominios
Detalles técnicosDNS, SAN de SSL, marcas de tiempo
ICANN OVERSIGHT
Acreditación y contexto RAA
Acreditación y contexto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Latest Classified Outcome 2026-08-14 12:53:33 UTC
Tecnologías · 2 identified
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Análisis de VirusTotal
Evidencias archivadas
Análisis del rendimiento del sitio
Google PageSpeed Insights — mobile performance audit of usdt-mix.top · checked Mar 2, 2026
Datos y informes externos
¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.