usdt-trx[.]io
“USDT-TRX自动兑换|TRX提前预支|USDT地址管理|USDT地址API监控|USDT交易多元化展示|USDT交易数据实时推送|T…”
usdt-trx.io — Контент недоступен (HTTP 502). Олицетворение бренда: Telegram; Тип мошенничества: Crypto Scam. Сводка доказательств: VirusTotal 2/93 (ESET, SOCRadar); URLQuery 2 alerts; PhishDestroy score 62/100. Регистратор: NameSilo.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
The domain usdt-trx.io is currently flagged as a brand impersonation and crypto‑related scam targeting Telegram users. The site was registered on February 21, 2026 through NameSilo, LLC and is hosted on the IP address 47.76.255.165, which resolves to a server located in Hong Kong and is announced by ASN 45102, Alibaba (US) Technology Co., Ltd. The authoritative nameservers are ns49.domaincontrol.com and ns50.domaincontrol.com. No TLS certificate is presented; the site operates without SSL, leaving communications unencrypted. Gridinsoft assigns a trust score of 0 out of 100, indicating a lack of credibility.
The page title captured in the intelligence reads "USDT-TRX自动兑换|TRX提前预支|USDT地址管理|USDT地址API监控|USDT交易多元化展示|USDT交易数据实时推送|TRX自动兑换机器人|加密", which lists a series of cryptocurrency exchange and monitoring services and confirms the crypto‑scam classification. VirusTotal reports that 2 of 93 security vendors have flagged the domain, and it appears on one known security blocklist, where it is also listed by PhishDestroy. The site impersonates the Telegram brand, aligning with the declared brand target. The current status is offline, but the elevated risk rating suggests that the infrastructure may be re‑activated.
Defenders should continue to block the domain at perimeter and DNS layers, monitor for any re‑appearance of the IP address or related subdomains, and add the domain to internal threat intel feeds. Given the absence of SSL and the zero trust score, any traffic to the domain should be treated as malicious. Ongoing observation of the registrar and hosting ASN is advised to detect potential migration attempts.
Данные сетевой безопасности Registrar context
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Hagezi Threat Feed | cdn.staticfile.org |
malicious | Sinkholed |
| DNS4EU | cdn.staticfile.org |
malicious | Sinkholed |
Процесс реагирования на угрозы
Статус в публичных блок-листах
Анализ VirusTotal
Доказательства и внешние отчеты
PD-20260125-A0A9A3 Recipient: abuse@namesilo.com Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание