usdt-qr[.]to
“Tether (USDT) QR Code Generator”
usdt-qr.to — Contenido no disponible (HTTP 502). Suplantación de marca: Ethereum; Tipo de estafa: Brand Impersonation. Resumen de las pruebas: VirusTotal 10/95 (alphaMountain.ai, BitDefender, CRDF, CyRadar, ESET); 3 external blocklist matches (Polkadot, Enkrypt, Codeesura); PhishDestroy score 80/100. Registrador: Government of Kingdom ….
El análisis detallado de PhishDestroy AI se mantiene en inglés para conservar el registro forense original.
This domain, usdt-qr.to, operates as a fraudulent cryptocurrency service impersonating Tether (USDT) and Ethereum infrastructure. The site presents itself as a legitimate USDT QR code generator, a common tactic used to deceive users into interacting with malicious smart contracts or disclosing wallet credentials. Analysis indicates the primary threat is a crypto drainer mechanism, where victims unknowingly authorize transactions that siphon funds from their wallets. The domain specifically targets Ethereum users, exploiting the popularity of QR-based transactions in decentralized finance (DeFi) ecosystems. Infrastructure analysis reveals multiple high-confidence indicators of compromise. The domain is flagged by 10 out of 95 security vendors on VirusTotal, including detection for phishing and malicious web content. It was registered on January 8, 2024, through the Government of Kingdom of Tonga registrar, a known jurisdiction for high-risk domains. The site resolves to IP address 45.12.2.86, hosted under AS6698 (Virtual Systems LLC) in Ukraine, and appears on five distinct security blocklists, including PhishDestroy and PhishingDB. Notably, the domain lacks SSL encryption, further increasing exposure to man-in-the-middle attacks during data transmission. Users who visited usdt-qr.to should immediately revoke any wallet permissions granted through the site, as these may enable unauthorized fund transfers. It is critical to audit all recent transactions for anomalies and transfer remaining assets to a new, secure wallet address. Browser data, including cookies and cached credentials, should be cleared to eliminate residual session tokens. Given the domain's active status and high-risk classification, users are advised to monitor their wallets for unusual activity and report the incident to relevant blockchain security platforms for further investigation.
Proceso de respuesta ante amenazas Pipeline
Estado de la lista de bloqueados pública
Análisis de VirusTotal
Evidencias archivadas
Datos y informes externos
“I was misled into using a fake QR code generator which happens to contain the scam's wallet address: TDDrK1ZL3c1zAajZVwYXbHjPitdMQ7i4oJ. After payment, i realized the recipient address was not correct and i lost that fund to the scammer.”
¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.