qrco[.]de
Ringkasan bukti
qrco.de is currently observed serving a single HTTP 302 redirect that lands on a page titled “Just a moment…”. The redirect originates from IP address 13.33.187.122, which is mapped to a United States location within the Amazon CloudFront network. The TLS handshake presents an Amazon RSA 2048 M04 certificate, indicating the site is using Amazon‑issued TLS infrastructure. Network analysis shows the domain resolves exclusively to the CloudFront IP and leverages Cloudflare Browser Insights, Cloudflare services, and HTTP/3. These layers provide content delivery and performance optimization while also obscuring the true origin of the payload. The domain was registered on 24 March 2026, and its status remains active as of the report date, 12 July 2026. Open‑source threat feeds have recorded the domain in 27 AlienVault OTX pulses and on three public blocklists (PhishDestroy, ScamSniffer, CryptoFirewall). VirusTotal scans have resulted in six of ninety‑five security vendors flagging the host, and Gridinsoft assigns a trust score of ten out of one hundred. The observed behavior, combined with the classification “Crypto Drainer (wallet extracted)”, suggests the site is used to lure victims into authorizing cryptocurrency transactions that divert funds to attacker‑controlled wallets. While the redirect and hosting details are well documented, the exact payload delivered after the initial page and the specific wallet addresses targeted have not been publicly disclosed. Defenders should block DNS resolution for qrco.de, enforce strict outbound controls on cryptocurrency‑related API calls, and monitor for any anomalous HTTP/3 traffic to the identified IP. Continuous re‑evaluation of threat‑intel feeds is advised to capture any evolution of the infrastructure or additional indicators of compromise.
Data Coverage
Alur Tanggapan Ancaman Pipeline
Cakupan daftar blokir
10 sumber eksternal dipantau · snapshot tersimpan Tidak diketahui
10 sumber eksternal dipantau Belum diperiksa
Linimasa deteksi
-
Cloudflare Radar
Pemindaian Cloudflare Radar tersimpan · Buka pemindaian
Laporan komunitas
Dilaporkan oleh 1 anggota komunitas; pertama terlihat 24/03/2026
- Laporan tersimpan
- 2
- URL unik yang dilaporkan
- 5
Intelijen komunitas
2 laporan komunitas
KategoriPHISHING
@Stop Telegram
Intelijen Domain
Detail teknisDNS, nama TLS, dan stempel waktu
Intelijen Forensik
Teknologi
3 teknologi dengan keyakinan tinggi teridentifikasi
Analisis VirusTotal
Analisis Performa Situs
Google PageSpeed Insights — mobile performance audit of qrco.de · checked Mar 25, 2026
Apakah Anda Terpengaruh oleh Situs Ini?
Jika Anda memasukkan kredensial akun, informasi pribadi atau pembayaran, atau mengunduh file dari domain ini, segera ambil tindakan. Di bawah ini adalah sumber daya untuk membantu Anda melaporkan insiden tersebut dan melindungi diri Anda sendiri.
Laporkan kepada Pihak Berwenang di Daerah Anda
Pilih negara Anda untuk mendapatkan kontak resmi kejahatan dunia maya, atau membuat draf pengaduan →.
Periksa Domain Apa Pun
Analisis ancaman menggunakan daftar blokir yang disimpan, WHOIS, DNS, dan bukti pemindaian publik
Pindai SekarangLaporkan Phishing
Laporkan domain yang mencurigakan ke basis data ancaman kami — lindungi komunitas
LaporanPemberitahuan Ancaman Real-Time
Laporan phishing terbaru dan perubahan ketersediaan yang diamati
PantauTetap Terinformasi, Tetap Aman
Pantau ancaman secara langsung atau ajukan keberatan terhadap daftar ini jika Anda yakin ini merupakan false positive