usdtminer[.]click
“USDT MINER”
usdtminer.click — Conteúdo indisponível (HTTP 502). Resumo das evidências: VirusTotal 3/93 (alphaMountain.ai, Gridinsoft, Webroot); PhishDestroy score 65/100. Registrador: Isimtescil Bilisim A.S.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
This domain functions as a generic phishing infrastructure component that deploys a fabricated USDT mining interface to capture cryptocurrency wallet credentials or initiate unauthorized transfers. The site presents itself under the USDT MINER page title and targets users seeking digital asset mining opportunities, thereby enabling direct wallet drainage or credential harvesting through deceptive forms.
Infrastructure analysis reveals the domain was created on February 21 2026 and registered through Isimtescil Bilisim A.S. It resolves to IP address 2.59.117.26, appears on exactly one security blocklist, and receives flags from 3 out of 95 VirusTotal vendors. The resource is currently marked offline yet retains its registration record and historical DNS linkage to the observed phishing content.
Users who accessed the domain should immediately revoke any wallet approvals or API keys entered on the page, scan connected devices with updated endpoint detection tools, and monitor associated cryptocurrency addresses for unauthorized outflows. Review of recent transaction histories across linked exchanges and wallets is required, followed by rotation of any reused credentials. Continued observation of account activity for at least 30 days is recommended to detect delayed exploitation attempts.
Sinais de segurança
Inteligência de segurança de rede
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Captura armazenada
Inteligência de Domínios
Detalhes técnicosDNS, SANs do SSL, carimbos de data e hora
ICANN OVERSIGHT
Credenciamento e contexto RAA
Credenciamento e contexto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Análise do VirusTotal
Evidências arquivadas
Evidências e relatórios externos
PD-20260125-F3793F Recipient: domain@isimtescil.net Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo