Scam Website
This site is classified as Scam Website based on multiple risk signals, including 2 blacklist detections, no established public user-review history, and heuristic security signals. These risks are driven by active warning signals despite the site's longer domain history.
Figure 1. Trust signal radar for qrcc.me. Larger shaded area indicates stronger trust signals.
Positive signals:
strong independent trust
popular site
a long-term domain history (5.1 years)
an active SSL certificate (3 months)
Negative signals:
security-provider warnings
a malware or phishing blacklist detection (1)
heuristic signals associated with scam
automated caution checks
Last checked September 17, 2026 at 2:26 PM by
Gridinsoft Trust Model v2.5.4
Share this report?
Independent Gridinsoft analysis
What Gridinsoft observed on Qrcc.me
A Gridinsoft threat analyst reviewed the site directly and documented the evidence behind this decision.
Current review
Review ID
GMA-20260904210915-19660f3e
Reviewed
by Gridinsoft Threat Analyst
Analyst finding
QR Redirect Service — Exact-Code Review Required
Evidence basis
First-party site analysisExternal vendor intelligence: Contradictory context — not used for this decision
The operator root is a QRCodeChimp shortener and did not itself present a phishing workflow. Public sandboxes preserve exact historical QR-code abuse, but current replay found a mix of removed codes, changed destinations, an unavailable destination, and one unresolved destination rather than a reproducible whole-domain phishing object. The current Gridinsoft report has no broad Phishing category, while a fresh VirusTotal snapshot still displays a Gridinsoft phishing row without an exact object. Because this is an unbounded mutable redirect namespace, the correct current conclusion is inconclusive and exact-code-dependent, not a domain-wide Safe certification and not a domain-wide phishing claim based solely on a blacklist category.
Analyst findings
Info3
Info01
Historical phishing evidence is tied to exact QR codes
Public sandboxes preserve credible evidence that individual qrcc.me codes have participated in phishing-labeled chains. Current replay shows that some of those codes were removed, one was retargeted to a Nexent Bank application page, and one still names a destination that no longer resolves. This supports object-level abuse history, not a claim that the operator root or every tenant is currently phishing.
Info02
No current whole-domain phishing object was reproduced
The operator root did not present a phishing workflow, and the replayed exact objects did not produce a current captured credential receiver, malware file, payload, or hash. One current destination remained inaccessible for assessment. The present evidence therefore does not justify a domain-wide phishing claim, but it also does not certify the mutable QR namespace as Safe.
Info03
Current verdicts require the exact QR code and destination
The public Gridinsoft report and the VirusTotal Gridinsoft row remain inconsistent at the broad domain level. Because qrcc.me delegates mutable destinations to users, a defensible harmful verdict should identify the complete QR URL, current redirect chain, final destination, and observed harmful behavior. A domain-only blacklist row is not a substitute for that object evidence.
Review 7 documented observations
View evidence
01Content
The operator root returned HTTP 200 and identified qrcc.me as the URL-shortener host for QR codes created on QRCodeChimp. It linked to qrcodechimp.com and contained no login, credential request, automatic unrelated redirect, executable or archive delivery, or malware payload.
HTTP status200
Final URLhttps://qrcc.me/
Page elementThis is a URL Shortener site for QR Codes that are created on QRCodeChimp.
Public artifact URLhttps://www.qrcodechimp.com/
Analyst observationThe root is an operator surface, not a directory or representative sample of user-created QR destinations.
02Redirect
The exact QR URL highlighted by a February 2026 sandbox remained active. Its current redirect script exposed http://onelink.to/ceb_app, which returned HTTP 307 to the Nexent Bank App page. The current chain did not present a fake login, credential receiver, automatic executable or archive download, malware file, payload, or hash.
HTTP status200
Redirect destinationhttp://onelink.to/ceb_app
Final URLhttps://www.nexentbank.de/nexent-bank-app/
Page elementNexent Bank App
Analyst observationNo current impersonated sign-in form, credential receiver, executable or archive delivery, malware payload, or hash was reproduced in this exact chain.
03Historical content
Public sandboxes preserved object-specific abuse context for several exact codes. /sl53e61zxm5l was associated with a phishing chain to deltaegyplast.com and now returns HTTP 404. /skqmwin7ifd5 appeared in a phishing-tagged Triage record and now returns HTTP 404. /s4o6ten8tlcv still exposes https://adpbidfilesecure.nl/D/DOC.html, but that destination did not resolve during this review. These are exact-code findings, not evidence that every QR code or the operator root is malicious.
Public artifact URLhttps://any.run/report/f4e1f669c14ab0c5dd76d4d4039f8a4bf956c80c7434a8a20b2d305eca383b52/e7397e98-c721-4a76-9636-4ba4904aba56
Public artifact URLhttps://tria.ge/
Public artifact URLhttps://any.run/report/d5daeabbf65f20f841ae0aa15ac804f42b754e51a5d14a79ca114b11ecf51138/0e0cde32-6b3a-4db8-adc1-09edf2b298fa
Analyst observationCurrent replay returned 404 for /sl53e61zxm5l and /skqmwin7ifd5.
DNS factadpbidfilesecure.nl did not resolve during the current review.
04Limitation
The exact code /sbdemb09bqiv, referenced by a 2024 phishing-tagged sandbox, currently returned a QR redirect page naming a perspectivefunnel.co destination. The destination returned an access-challenge response during this review, so its underlying current content and forms were not assessed and no current harmful or clean conclusion was assigned to this object.
Public artifact URLhttps://any.run/report/107218d78a4ba9148c2cddd62b75d185b29a584999adf11fa921cecda81518fa/476b2e41-6b58-4123-9078-167a8a1d3421
Analyst observationThe destination's underlying current content was not available for direct assessment; this object remains unresolved rather than classified clean or harmful.
05Historical content
urlscan reported 490 public records and its current 100-result page contained no result-level malicious verdict. OTX exposed one 2024 Phishing Army blocklist pulse and 117 URL observations; none of the available OTX URL rows carried a Google Safe Browsing match. Public search also returned several exact-code sandbox records. The Internet Archive CDX service and Common Crawl index were unavailable during this pass; the prior signed review recorded 324 distinct successful Wayback URL records from 2022 through 2025.
Public artifact URLhttps://urlscan.io/domain/qrcc.me
Public artifact URLhttps://otx.alienvault.com/indicator/domain/qrcc.me
Public artifact URLhttps://web.archive.org/web/*/qrcc.me/*
Analyst observationurlscan reported 490 total public records; the returned recent 100-result page exposed no result-level malicious verdict.
Analyst observationOTX returned 117 URL observations and one broad 2024 blocklist pulse; none of the available URL rows contained a Google Safe Browsing match.
Analyst observationUnavailable archive interfaces were treated as unknown; prior signed archive counts were retained only as historical context.
06HTTP response
The current Gridinsoft public report did not show an active Phishing or other broad security category for qrcc.me. A fresh VirusTotal domain snapshot nevertheless still displayed the Gridinsoft row as phishing. This is a broad cross-platform classification discrepancy and does not identify an exact QR code, destination, phishing form, credential receiver, malware file, payload, or hash.
Public artifact URLhttps://gridinsoft.com/online-virus-scanner/url/qrcc-me
Public artifact URLhttps://www.virustotal.com/gui/domain/qrcc.me
Page elementThe current Gridinsoft report does not display an active Phishing category.
Analyst observationThe current VirusTotal domain snapshot retained a broad Gridinsoft phishing row without naming an exact QR object or observed harmful behavior.
07Limitation
qrcc.me is a mutable user-controlled redirect namespace without a complete public directory. Destinations can be changed, removed, conditioned on client context, or kept private. A clean operator root and finite current sample cannot support a whole-domain Safe verdict, while a historical sandbox label or bare domain blacklist category cannot establish that every QR code is phishing.
Analyst observationThe operator root states that qrcc.me hosts QRCodeChimp QR links, and exact QR pages expose independently selected destinations.
Analyst observationThe complete private, unindexed, deleted, conditional, geographic, device-dependent, and future QR-code namespace is not publicly enumerable.
Analyst observationEvery reported QR URL requires review of its exact current redirect chain and destination.
Scope and limitations
The review covered the operator root, the exact code raised by the prior public sandbox, four additional exact sandbox-indexed codes, exposed redirect scripts, representative destinations, current public Gridinsoft and VirusTotal state, urlscan, OTX, public sandbox indexes, and available archive interfaces.
The complete private, unindexed, deleted, conditional, account-bound, geographic, device-dependent, changed, and future QR namespace cannot be publicly enumerated.
The perspectivefunnel.co destination named by /sbdemb09bqiv returned an access-challenge response, so its underlying current content and forms were not assessed and the object remains unresolved.
The adpbidfilesecure.nl destination named by /s4o6ten8tlcv did not resolve, so its current content could not be tested; the dead destination is not treated as proof of current phishing or safety.
The Internet Archive CDX and Common Crawl interfaces were unavailable during this pass. Earlier signed archive counts were used only as historical context, and unavailable sources were treated as unknown rather than clean.
Public scanner, sandbox, threat-intelligence, and archive indexes are finite. A current harmful or clean verdict for any QR code requires its exact URL, redirect chain, final destination, and observable behavior.
What is Qrcc?
Qrcc.me is in our scam category. This label is used for domains linked to deceptive offers, non-fulfillment after payment, or data collection under false pretenses.
What users usually see: copied branding, fake trust badges, edited reviews, and checkout pressure (timers, "last items", "verify payment"). These signals are easy to fake and should not be treated as proof of legitimacy.
Safety step: do not send documents, card photos, or wallet transfers. If a payment was already made, contact your bank/provider immediately and preserve receipts, URLs, and message screenshots.
🚨
Gridinsoft blocks this website because it was classified as scam website.
No. Based on current analysis, qrcc.me falls in the Danger Zone and should not be treated as a safe website unless legitimacy is independently confirmed through highly trusted sources.
What are the risks of qrcc.me?
This website shows multiple red flags commonly associated with scam websites.
Why is qrcc.me marked "Scam Website"?
Gridinsoft evaluates qrcc.me, focusing on suspicious content indicators (Low Scamadviser Score, Heuristic - Scam, Heuristic Risk), hosting technology and infrastructure, SSL certificate status, website reputation across multiple databases, customer reviews from various independent platforms. We weigh these indicators to calculate the trust score.
Note: Automated systems are not perfect — while the evidence suggests risk, there is still a chance the site is legitimate. We recommend you check the website using detailed analysis or by contacting the company directly through verified channels.
A structured view of the site's detected themes, page signals, and related online footprint elements.
Popular Site
This site shows elevated traffic signals relative to similar domains; this is generally positive but does not by itself prove legitimacy.
Low Scamadviser Score
Independent security assessment from Scamadviser indicates this site has received a low trust rating, suggesting potential security risks or operational concerns requiring user caution.
Heuristic - Scam
Heuristic Risk
Established Domain
qrcc.me has maintained active domain presence over time, indicating operational continuity.
External provider warnings: 2/27 Scam Website
This section shows what independent external security sources say about this site.
A warning appears when one or more sources report malware, phishing, abuse, or other safety concerns. Each row shows the source and its verdict.
If no source reports a warning, the site is shown as clear in this section.
VIPRE
Malware
Scamadviser
Warned
External provider results for Qrcc.me, last checked September 17, 2026.
— VirusTotal
Domain Information
CreatedAugust 2, 2021 at 3:40 PMUpdated: August 12, 2026 at 6:44 AM · Expires: August 2, 2027 at 3:40 PM
Domain Age5.1 years
RegistrantGridinsoft privacy protected
IS (Iceland)
Domain StatusClient Transfer ProhibitedDNSSEC: UNSIGNED
Top Level Domain.meGeneric TLD
Technical Details
IP Address52.21.163.87
Hostnameec2-52-21-163-87.compute-1.amazonaws.com
Hosting ProviderAS14618 Amazon.com, Inc.Ashburn, Virginia, US
SSL CertificateYE2TLS 1.3 · Valid for: 3 months · from August 9, 2026 at 1:22 AM · to November 7, 2026 at 1:22 AM
Name Serversdns1.registrar-servers.com dns2.registrar-servers.com
Content Analysis
Mentioned hosts (2)
www.qrcodechimp.comqrcc.me
How popular is this website?
Popularity
129 653
Qrcc.me falls outside the top 100,000 websites globally, which typically indicates a more specialized or localized audience.
Loading...
Signs You're Dealing With an Online Scam
Scammers have devised new ways to deceive users, and what was relevant ten years ago may not be applicable today. In this post, we have compiled the most current types of online scams.
If you own Qrcc.me and want to challenge the trust score, please submit a review request via portal.gridinsoft.com. There you can claim your profile and add verified company/contact details. If you cannot access the portal, email legal(at)gridinsoft.com with proof of legitimacy and contact details. We never charge website owners for reviews or reconsideration requests. For more information, please review our Disclaimer.
Leave a review
10
points /100
The score is based on a 1-100 scale, with 100 being the most reputable.
Check another website
Verify the security of domains and services based on 10M+ real websites.
Is This Your Website?
Think your website was scored unfairly? Request a reevaluation and our team will take another look.
A website report warns you. A PC scan protects you.
Unsafe sites can leave adware, unwanted apps, or hidden malware in downloads and browser settings. Run Gridinsoft Anti-Malware to check what may already be on this Windows PC.
Checks active threats, startup items, and suspicious downloads
Finds adware and unwanted apps linked to unsafe websites
Shows scan results before you decide what to remove
Your comment is currently undergoing moderation and will be published shortly.
Help protect others by sharing this page on social media! The more people who know about qrcc.me, the fewer chances they have to deceive someone else.Help others evaluate qrcc.me by sharing this page on social media!
Help protect others by sharing this page on social media! The more people who know about qrcc.me, the fewer chances they have to deceive someone else. Help others evaluate qrcc.me by sharing this page on social media!