btc-qr[.]to
“Bitcoin QR Code Generator”
btc-qr.to — Контент недоступний. Уособлення бренду: Bitcoin; Тип шахрайства: Crypto Scam. Зведення доказів: VirusTotal 12/95 (alphaMountain.ai, BitDefender, CRDF, CyRadar, Fortinet); 4 external blocklist matches; PhishDestroy score 86/100. Реєстратор: Government of Kingdom ….
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
As of July 23, 2026, the domain btc-qr.to is flagged as a high-risk brand impersonation domain, specifically targeting Bitcoin. The domain, which was created on January 08, 2024, is currently offline and has been taken down. Analysis indicates that the domain has been listed in 16 threat intelligence pulses on AlienVault OTX, further emphasizing its suspicious nature. The domain is known to impersonate Bitcoin and operates under the page title 'Bitcoin QR Code Generator.' This domain is registered through the Government of the Kingdom of Tonga, which is an uncommon registrar for legitimate crypto-related services.
The nameservers, ns1.zomro.net and ns2.zomro.ru, suggest that the domain is hosted by Virtual Systems LLC in Ukraine, adding another layer of potential risk. The absence of an SSL certificate also raises concerns, as most legitimate websites use HTTPS for secure connections. Gridinsoft has assigned the domain a trust score of 0/100, indicating that it is highly untrustworthy.
The domain appears on five security blocklists, including PhishDestroy, ScamSniffer, Polkadot, Enkrypt, and Codeesura, which suggests that it has been identified as a threat by multiple security providers. In the context of the current status and historical indicators, defenders should treat btc-qr.to with extreme caution and ensure that it remains blocked in their security systems. Even though the domain is offline, it could be reactivated at any time, and its previous high-risk status makes it a potential threat for future attacks.
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Аналіз VirusTotal
Архівні докази
Докази та зовнішні звіти
“Warning to the ChainAbuse community: The operator from Russia (🇷🇺) who goes by the pseudonyms "icryptofbi", "cryptofbi007", "Olgareva" or "@gabrielenesto1 (Gabriel Enesto)" of the crypto QR code phishing network (https://bitcointalk.org/index.php?topic=5475430.0) is also running fake cryptocurrency mixer phishing scam websites. The domains to be cautious of include: - eth-mixer.to (Archive: https://archive.is/I9Bnq) - btc-mixer.to (Archive: https://archive.is/TaqxC) - ltc-mixer.to (Archive”
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога