usdt-buyer[.]duckdns[.]org
“USDT Buyer â Institutional OTC Desk”
usdt-buyer.duckdns.org — Прикритий · доступний. Тип шахрайства: Crypto Drainer. Зведення доказів: VirusTotal 10/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, CyRadar, Fortinet); Google Safe Browsing flagged; cloaking observed; PhishDestroy score 88/100. Реєстратор: DuckDNS.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
The domain usdt-buyer.duckdns.org has been identified as a crypto drainer scam targeting users under the guise of an institutional over-the-counter (OTC) trading desk for Tether (USDT). Analysis indicates this domain is designed to deceive victims into transferring cryptocurrency, which is then siphoned to attacker-controlled wallets. The domain is currently offline, but prior activity and infrastructure details confirm its malicious intent. Technical indicators reveal the domain was flagged by 12 of 95 security vendors on VirusTotal, with Google Safe Browsing specifically categorizing it as a social engineering threat. It resolved to the IP address 80.241.222.114 and was registered through DuckDNS, a dynamic DNS provider often abused for malicious purposes. The site was hosted on an Ubuntu server running Nginx, and it employed a Let's Encrypt SSL certificate to appear legitimate. Gridinsoft assigned a trust score of 0/100, and the domain appeared on at least one security blocklist. The page title, 'USDT Buyer — Institutional OTC Desk,' further supports the conclusion that it impersonated a legitimate trading service to exploit victims. Current status confirms the domain has been taken offline, but similar threats may reemerge under different domains or IPs. Users are advised to verify all cryptocurrency transaction destinations through official channels, avoid interacting with unsolicited OTC desk offers, and monitor wallet addresses for unauthorized transfers. Network administrators should block the IP 80.241.222.114 and any associated domains registered through DuckDNS with similar naming patterns. Cryptocurrency platforms should alert users to this specific scam vector and implement additional verification steps for high-value transactions.
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Збережений знімок
Аналітика доменів
Технічні деталіDNS, SAN-адреси SSL, мітки часу
Технології · 2 identified
Ubuntu is a free and open-source operating system on Linux for the enterprise server, desktop, cloud, and IoT.
www.ubuntu.com 100% впевненостіNginx is a web server that can also be used as a reverse proxy, load balancer, mail proxy and HTTP cache.
nginx.org 100% впевненостіАналіз VirusTotal
Аналіз продуктивності сайту
Google PageSpeed Insights — mobile performance audit of usdt-buyer.duckdns.org · checked Jun 26, 2026
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога