VirusTotal
12 / 91
“USDT to TRX Exchange USA – Fast & Easy Crypto Swap”
The sent-report ledger records the first outgoing report at .
The recorded recipient is abuse@godaddy.com.
The latest stored availability evidence still shows the domain reachable; 6 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
usdttotrx.exchange is a confirmed crypto drainer phishing site targeting TRX/USDT swaps. Zero detections on VirusTotal, but blocked by security blocklists.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
12 / 91
1 threat-system alert
Повідомитиchecked — no match recorded
no community references
Повідомитизбережений звіт
Повідомити Аналіз завершено
Повідомити12 перевірено — блокувань немає
Report stored; verdict not recorded
ПовідомитиChecked; no threat flag recorded
Повідомити| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | usdttotrx.exchange |
malicious | Sinkholed |
This domain is flagged as an active crypto drainer phishing operation designed to intercept and siphon cryptocurrency transactions, specifically targeting users attempting USDT to TRX exchanges. Analysis indicates the site employs social engineering tactics to trick victims into authorizing malicious smart contract interactions, leading to unauthorized fund transfers from connected wallets. The threat type is classified as a crypto asset drainer, distinct from generic credential theft or brand impersonation schemes. Infrastructure analysis reveals multiple high-risk indicators. The domain usdttotrx.exchange was registered on April 07, 2026, through GoDaddy.com, LLC, with a suspiciously recent creation date suggesting rapid deployment for malicious purposes. It resolves to the IP address 104.21.11.191, which may be associated with content delivery networks used to mask origin infrastructure. Despite zero detections out of 95 engines on VirusTotal, the domain appears on at least one security blocklist and is actively blocked by PhishDestroy. The Gridinsoft trust score of 0 out of 100 further corroborates the high-risk classification. The SSL certificate issued by Let's Encrypt provides basic encryption but does not validate legitimacy, as free certificates are commonly exploited by threat actors. Mitigation requires immediate action from both end users and security teams. Users who have interacted with this domain should revoke all smart contract authorizations granted to unknown or suspicious addresses via their wallet interfaces, particularly those linked to TRX or USDT transactions. Cryptocurrency holders are advised to verify exchange platforms through official channels only and avoid clicking on links from unsolicited communications. Security teams should implement network-level blocking of the domain and its resolving IP address, monitor for outbound connections to 104.21.11.191, and update endpoint protection rules to flag any wallet interactions originating from this infrastructure. Transaction monitoring systems should be configured to alert on unusual TRX or USDT movements to addresses previously associated with this domain.
Збережені дані спостережень за взаємодією веб-сканера та браузера для цього хоста, а також перевірка відбитків у режимі реального часу для систем розподілу трафіку типу «Кейтаро».
cloudflareПримітка щодо сканера: cloudflare_ban: raw=cf_phishing_block; http=403; via=https_proxy; server=cloudflare; provider_error=cloudflare_phishing_interstitial
Реакція провайдера під час сканування: cloudflare_phishing_interstitial
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Репутація Edge-IP не пов’язана з цим доменом.
craig.ns.cloudflare.comLocation describes the IP network.
8e7c173f575d44a6ea8395e60c1a669412ec02ba6fc0a510509256ecd4c888e1Saved certificate metadata. Certificate dates without a timezone are shown as stored. Transport encryption does not establish that the site is trustworthy.
Google PageSpeed Insights — mobile performance audit of usdttotrx.exchange · checked Jun 26, 2026
8 recorded events. These records describe collected evidence, outgoing notifications and publication; they do not confirm a complete investigation or a takedown.
We scan suspicious URLs, inspect public results and send evidence through the appropriate abuse-reporting channels. The dated events above show what is recorded for this domain. The directory below explains the wider workflow.
Capture the rendered page, requests and visible infrastructure.
Compare the available engine results and retain the analysis timestamp.
Check whether Google currently lists the URL as unsafe.
Inspect a public scan and its recorded network and classification data.
Look for indicator references and related community intelligence.
Compare archived captures and preserve historical context.
Look for matching indicators and associated threat records.
Inspect certificate records and related hostnames.
Compare security resolver responses and record observed blocking.
Inspect the public DNS, TLS, HTTP and technology surface.
Security services used for scanning, reputation checks and reporting are listed below. A service being listed is not evidence that it received, accepted or acted on this particular domain. Recorded submissions appear in the notification history above.
Повідомив 1 учасник спільноти; уперше помічено 07.04.2026
PD-20260407-CEE7B2 Recipient: abuse@godaddy.com Registrar: GoDaddy.com LLC (United States) Policy Violations: Universal TOS + Abuse Policy prohibit fraudulent, abusive, malicious, phishing and illegal activity; grants right to terminate or suspend services Applicable Laws: CFAA 18 U.S.C. §1030, Wire Fraud 18 U.S.C. §1343, CAN-SPAM Act
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Template-based draft · optional AI wording assistance requires separate consent
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразДодавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиОстанні звіти про фішинг і помічені зміни доступності
ВідстежуватиСлідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога