btc-qr[.]to
“Bitcoin QR Code Generator”
btc-qr.to — Conteúdo indisponível. Representação da marca: Bitcoin; Tipo de golpe: Crypto Scam. Resumo das evidências: VirusTotal 12/95 (alphaMountain.ai, BitDefender, CRDF, CyRadar, Fortinet); 4 external blocklist matches; PhishDestroy score 86/100. Registrador: Government of Kingdom ….
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
As of July 23, 2026, the domain btc-qr.to is flagged as a high-risk brand impersonation domain, specifically targeting Bitcoin. The domain, which was created on January 08, 2024, is currently offline and has been taken down. Analysis indicates that the domain has been listed in 16 threat intelligence pulses on AlienVault OTX, further emphasizing its suspicious nature. The domain is known to impersonate Bitcoin and operates under the page title 'Bitcoin QR Code Generator.' This domain is registered through the Government of the Kingdom of Tonga, which is an uncommon registrar for legitimate crypto-related services.
The nameservers, ns1.zomro.net and ns2.zomro.ru, suggest that the domain is hosted by Virtual Systems LLC in Ukraine, adding another layer of potential risk. The absence of an SSL certificate also raises concerns, as most legitimate websites use HTTPS for secure connections. Gridinsoft has assigned the domain a trust score of 0/100, indicating that it is highly untrustworthy.
The domain appears on five security blocklists, including PhishDestroy, ScamSniffer, Polkadot, Enkrypt, and Codeesura, which suggests that it has been identified as a threat by multiple security providers. In the context of the current status and historical indicators, defenders should treat btc-qr.to with extreme caution and ensure that it remains blocked in their security systems. Even though the domain is offline, it could be reactivated at any time, and its previous high-risk status makes it a potential threat for future attacks.
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Análise do VirusTotal
Evidências arquivadas
Evidências e relatórios externos
“Warning to the ChainAbuse community: The operator from Russia (🇷🇺) who goes by the pseudonyms "icryptofbi", "cryptofbi007", "Olgareva" or "@gabrielenesto1 (Gabriel Enesto)" of the crypto QR code phishing network (https://bitcointalk.org/index.php?topic=5475430.0) is also running fake cryptocurrency mixer phishing scam websites. The domains to be cautious of include: - eth-mixer.to (Archive: https://archive.is/I9Bnq) - btc-mixer.to (Archive: https://archive.is/TaqxC) - ltc-mixer.to (Archive”
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo