web[.]qbtxtrint[.]com
“Q-A-T”
web.qbtxtrint.com — Контент недоступний (HTTP 502). Уособлення бренду: Genericscam; Тип шахрайства: Crypto Drainer. Зведення доказів: VirusTotal 5/91 (ChainPatrol, CRDF, Gridinsoft, Netcraft, SOCRadar); URLQuery 1 alert; URLScan malicious verdict; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 78/100. Реєстратор: NameSilo.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
PhishDestroy identifies the active domain web.qbtxtrint.com as a crypto-drainer currently stealing digital assets from unsuspecting visitors. This site is designed to trick users into connecting their cryptocurrency wallets and then silently drain funds without additional confirmation. Because the page appears legitimate at first glance—using a valid Let’s Encrypt SSL certificate—users may not realize they are on a malicious site until it is too late. Once connected, wallet-stealing scripts automatically initiate unauthorized transfers to attacker-controlled addresses, often draining balances within seconds. Always inspect the URL and avoid clicking links in unsolicited messages or unfamiliar websites.
This domain was flagged by PhishDestroy after analysis revealed critical threat indicators. According to our telemetry, web.qbtxtrint.com resolves to IP 154.16.170.58 and currently shows zero detections out of 95 VirusTotal engines as of seed 780603. The domain was created on June 24, 2025, and is registered through NameSilo, LLC, a common bulk-registration provider often exploited by threat actors to spin up disposable phishing pages. These technical markers—combined with the absence of AV coverage—indicate a rapidly evolving threat that has not yet been widely blocked, increasing the risk of successful compromise.
If you visited web.qbtxtrint.com or entered any wallet credentials, take immediate action to protect your assets. Disconnect your wallet from the site, revoke any unauthorized connections via your wallet’s connection manager, and transfer remaining funds to a new, clean wallet. Scan your device with reputable antivirus software and consider rotating all private keys or seed phrases used on the affected machine. Report the incident to your wallet provider and PhishDestroy using seed 780603 to help block this campaign. Stay vigilant—new domains like this emerge daily, and only verified, trusted sources should be used for cryptocurrency transactions.
Розвіддані з мережевої безпеки Registrar context
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Private YARA rules | www.youtube.com/s/player/8456c9de/player_embed_es6.vflset/en_us/base.js |
audit | Hunting_JS_WebAssembly |
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Збережений знімок
Аналітика доменів
Технічні деталіDNS, SAN-адреси SSL, мітки часу
ICANN OVERSIGHT
Registration: qbtxtrint.com
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For the registrable domain qbtxtrint.com behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Технології · 8 identified
amCharts is a JavaScript-based interactive charts and maps programming library and tool.
amcharts.com 100% впевненостіYouTube is a video sharing service where users can create their own profile, upload videos, watch, like and comment on other videos.
www.youtube.com 100% впевненостіBootstrap is a free and open-source CSS framework directed at responsive, mobile-first front-end web development. It contains CSS and JavaScript-based design templates for typography, forms, buttons, navigation, and other interface components.
getbootstrap.com 100% впевненостіApache is a free and open-source cross-platform web server software.
httpd.apache.org 100% впевненостіMoment.js is a free and open-source JavaScript library that removes the need to use the native JavaScript Date object directly.
momentjs.com 100% впевненостіjQuery is a JavaScript library which is a free, open-source software designed to simplify HTML DOM tree traversal and manipulation, as well as event handling, CSS animation, and Ajax.
jquery.com 100% впевненостіPopper is a positioning engine, its purpose is to calculate the position of an element to make it possible to position it near a given reference element.
popper.js.org 100% впевненостіАналіз VirusTotal
Аналіз продуктивності сайту
Google PageSpeed Insights — mobile performance audit of web.qbtxtrint.com · checked Apr 27, 2026
Докази та зовнішні звіти
PD-20260427-95E8CC Recipient: abuse@namesilo.com Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога