check-usdt[.]info
“front-end”
check-usdt.info — Belum terverifikasi. Peniruan identitas merek: Genericcrypto; Jenis penipuan: Crypto Drainer. Ringkasan bukti: VirusTotal 12/91 (alphaMountain.ai, BitDefender, CRDF, ESET, Fortinet); URLQuery 1 det.; URLScan malicious verdict; Spamhaus DBL_PHISH; PhishDestroy score 88/100. Registrar: NiceNIC.
Analisis terperinci PhishDestroy AI di bawah tetap berbahasa Inggris untuk menjaga catatan forensik asli.
This domain, check-usdt.info, is a confirmed phishing site designed to steal cryptocurrency. It likely mimics a legitimate crypto service, tricking users into connecting their wallets or entering private keys, which then get drained of funds. The threat is known as a 'crypto drainer' — once you interact, your assets can be stolen instantly.
PhishDestroy's investigation reveals that check-usdt.info was created on April 11, 2026, and was quickly identified as malicious. VirusTotal shows 6 out of 95 security vendors flagging it, and it appears on one security blocklist. The site was registered through NICENIC INTERNATIONAL GROUP CO., LIMITED and used a Let's Encrypt SSL certificate (E7) to appear legitimate. It was hosted at IP 172.67.183.244 and has since been taken offline.
If you visited check-usdt.info or connected your wallet, immediately revoke any permissions via your wallet's settings or use a revoke tool. Never share your seed phrase or private keys. Monitor your accounts for unauthorized transactions and consider moving funds to a new wallet. Always verify URLs on PhishDestroy before connecting your wallet to any site.
Intelijen Keamanan Jaringan Registrar context
Alur Tanggapan Ancaman Pipeline
Status Daftar Blokir Publik
Tangkapan tersimpan
Intelijen Domain
Rincian teknisDNS, SAN SSL, cap waktu
ICANN OVERSIGHT
Akreditasi dan konteks RAA
Akreditasi dan konteks RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Latest Classified Outcome 2026-08-13 12:53:31 UTC
Teknologi · 7 identified
JavaScript runtime built on Chrome V8 engine for server-side development.
Progressive JavaScript framework for building user interfaces.
Free public CDN for open-source projects, serving files from npm and GitHub.
Performance monitoring tool that measures website speed from real users.
www.cloudflare.comWeb infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Analisis VirusTotal
Bukti Terarsip
Bukti & Laporan Eksternal
PD-20260414-3D541F Recipient: abuse@nicenic.net, abuse@identitydigital.com Apakah Anda Terpengaruh oleh Situs Ini?
Jika Anda memasukkan kredensial akun, informasi pribadi atau pembayaran, atau mengunduh file dari domain ini, segera ambil tindakan. Di bawah ini adalah sumber daya untuk membantu Anda melaporkan insiden tersebut dan melindungi diri Anda sendiri.
Laporkan kepada Pihak Berwenang di Daerah Anda
Pilih negara Anda untuk mendapatkan kontak resmi kejahatan dunia maya, atau membuat draf pengaduan →.
Periksa Domain Apa Pun
Analisis ancaman menggunakan daftar blokir yang disimpan, WHOIS, DNS, dan bukti pemindaian publik
Pindai SekarangLaporkan Phishing
Laporkan domain yang mencurigakan ke basis data ancaman kami — lindungi komunitas
LaporanPemberitahuan Ancaman Real-Time
Laporan phishing terbaru dan perubahan ketersediaan yang diamati
PantauTetap Terinformasi, Tetap Aman
Pantau ancaman secara langsung atau ajukan keberatan terhadap daftar ini jika Anda yakin ini merupakan false positive