Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is complaint@gname.com.
The latest stored availability evidence still shows the domain reachable; 6 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
usdt[.]6-i[.]cc
“虚拟货币投资平台”
usdt.6-i.cc — Non vérifié. Type d'arnaque : Credential Phishing. Résumé des preuves: VirusTotal 4/91 (Chong Lua Dao, CRDF, Forcepoint ThreatSeeker, Gridinsoft); PhishDestroy score 71/100. Bureau d’enregistrement: Gname.
L’analyse détaillée de PhishDestroy AI reste en anglais afin de préserver le relevé forensique original.
This domain, usdt.6-i.cc, is identified as a cryptocurrency credential theft operation designed to deceive users into disclosing wallet credentials or transferring funds to fraudulent accounts. The site masquerades as a legitimate virtual currency investment platform, using the Chinese title '虚拟货币投资平台' to target individuals interested in cryptocurrency trading. Analysis indicates the site employs social engineering tactics, such as fake login portals and investment dashboards, to harvest sensitive information or redirect victims to malicious smart contracts that drain wallet balances. Infrastructure analysis reveals multiple high-risk indicators confirming the domain's malicious nature. The domain was registered on February 21, 2026, through Gname.com Pte. Ltd., an uncommon registrar for legitimate financial services. It resolves to the IP address 104.19.169.112 and is currently offline, though it remains flagged by 6 out of 95 security vendors on VirusTotal. The site employed Cloudflare for hosting, a common tactic to obscure server origins, and utilized Node.js with Express for backend operations, alongside HSTS to create a false sense of security. Additionally, the domain appears on one security blocklist and was previously blocked by automated phishing detection systems. Users who visited usdt.6-i.cc should take immediate action to mitigate potential risks. First, disconnect any devices used to access the site from the internet and run a full antivirus scan to detect malware or unauthorized scripts. If wallet credentials or private keys were entered, transfer remaining funds to a new, secure wallet and revoke any connected smart contract approvals. Monitor financial accounts and transaction histories for unauthorized activity, and report the incident to relevant cryptocurrency exchanges or fraud reporting platforms. Avoid interacting with any communications or links associated with this domain, as they may lead to further exploitation.
Processus de réponse aux menaces Pipeline
Statut de la liste de blocage publique
Technologies · 4 identified
JavaScript runtime built on Chrome V8 engine for server-side development.
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comAnalyse VirusTotal
Preuves archivées
Analyse des performances du site
Google PageSpeed Insights — mobile performance audit of usdt.6-i.cc · checked Jun 27, 2026
Données factuelles et rapports externes
PD-20260203-97663B Recipient: complaint@gname.com Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif