usdt365[.]q38[.]online
“q38.co”
usdt365.q38.online — Прикритий · доступний. Тип шахрайства: Fake Exchange. Зведення доказів: VirusTotal 4/91 (alphaMountain.ai, CRDF, Gridinsoft, SOCRadar); cloaking observed; PhishDestroy score 86/100. Реєстратор: NameCheap.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
Analysis of the domain usdt365.q38.online indicates an active phishing campaign targeting cryptocurrency users, classified as a fake exchange scam. The domain was registered on April 7, 2026, through NameCheap, Inc., and currently resolves to the IP address 64.29.17.65, hosted by a provider in the United States. Infrastructure analysis reveals the use of Cloudflare nameservers (dolly.ns.cloudflare.com and tosana.ns.cloudflare.com), a common tactic to obscure hosting details and evade takedowns. The domain presents a page title of 'q38.co,' though the exact content and functionality of the site remain unconfirmed as of this report. Security vendor detections are limited but notable: four of ninety-four engines flagged the domain as malicious, and it appears on at least one security blocklist. The domain maintains a valid SSL certificate issued by Let's Encrypt, which may lend a superficial appearance of legitimacy to unsuspecting users. The Gridinsoft trust score of 0/100 further supports the assessment of high risk. While the specific lure or mechanism of the scam is not detailed in available data, the classification as a fake exchange suggests an attempt to deceive users into depositing cryptocurrency or divulging credentials. Defenders should prioritize blocking this domain at the DNS and network levels, particularly in environments where cryptocurrency-related activity is common. Monitoring for related subdomains or newly registered domains under the q38.online parent may reveal additional infrastructure tied to this campaign. Given the domain's recent registration and active status, continued vigilance is warranted, as threat actors frequently rotate or expand infrastructure in response to detection.
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Збережений знімок
Аналітика доменів
Технічні деталіDNS, SAN-адреси SSL, мітки часу
ICANN OVERSIGHT
Registration: q38.online
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For the registrable domain q38.online behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Аналіз VirusTotal
Аналіз продуктивності сайту
Google PageSpeed Insights — mobile performance audit of usdt365.q38.online · checked Jun 26, 2026
Докази та зовнішні звіти
PD-20260407-807D60 Recipient: abuse@vercel.com Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога