usdt-qr[.]to
“Tether (USDT) QR Code Generator”
usdt-qr.to — Контент недоступний (HTTP 502). Уособлення бренду: Ethereum; Тип шахрайства: Brand Impersonation. Зведення доказів: VirusTotal 10/95 (alphaMountain.ai, BitDefender, CRDF, CyRadar, ESET); 3 external blocklist matches (Polkadot, Enkrypt, Codeesura); PhishDestroy score 80/100. Реєстратор: Government of Kingdom ….
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
This domain, usdt-qr.to, operates as a fraudulent cryptocurrency service impersonating Tether (USDT) and Ethereum infrastructure. The site presents itself as a legitimate USDT QR code generator, a common tactic used to deceive users into interacting with malicious smart contracts or disclosing wallet credentials. Analysis indicates the primary threat is a crypto drainer mechanism, where victims unknowingly authorize transactions that siphon funds from their wallets. The domain specifically targets Ethereum users, exploiting the popularity of QR-based transactions in decentralized finance (DeFi) ecosystems. Infrastructure analysis reveals multiple high-confidence indicators of compromise. The domain is flagged by 10 out of 95 security vendors on VirusTotal, including detection for phishing and malicious web content. It was registered on January 8, 2024, through the Government of Kingdom of Tonga registrar, a known jurisdiction for high-risk domains. The site resolves to IP address 45.12.2.86, hosted under AS6698 (Virtual Systems LLC) in Ukraine, and appears on five distinct security blocklists, including PhishDestroy and PhishingDB. Notably, the domain lacks SSL encryption, further increasing exposure to man-in-the-middle attacks during data transmission. Users who visited usdt-qr.to should immediately revoke any wallet permissions granted through the site, as these may enable unauthorized fund transfers. It is critical to audit all recent transactions for anomalies and transfer remaining assets to a new, secure wallet address. Browser data, including cookies and cached credentials, should be cleared to eliminate residual session tokens. Given the domain's active status and high-risk classification, users are advised to monitor their wallets for unusual activity and report the incident to relevant blockchain security platforms for further investigation.
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Аналіз VirusTotal
Архівні докази
Докази та зовнішні звіти
“I was misled into using a fake QR code generator which happens to contain the scam's wallet address: TDDrK1ZL3c1zAajZVwYXbHjPitdMQ7i4oJ. After payment, i realized the recipient address was not correct and i lost that fund to the scammer.”
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога