MALICIOUS — CRITICAL
tornadocashdao[.]com
Analysis of tornadocashdao.com, created on February 23, 2026, shows a high‑risk generic phishing infrastructure targeting users of the Tornado Cash service.
- VirusTotal
- 14/91
- Blocklists
- 2 · MetaMask, SEAL
- Verfügbarkeit
- Letzter bekanntermaßen aktiv · HTTP 301
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
tornadocashdao.com — Letzter bekanntermaßen aktiv (HTTP 301). Zusammenfassung der Beweislage: VirusTotal 14/91 (alphaMountain.ai, BitDefender, Chong Lua Dao, CRDF, CyRadar); 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 100/100. Registrar: Spaceship.
Die ausführliche Analyse von PhishDestroy AI bleibt auf Englisch, damit der ursprüngliche forensische Bericht unverändert bleibt.
Evidence Analysis
Analysis of tornadocashdao.com, created on February 23, 2026, shows a high‑risk generic phishing infrastructure targeting users of the Tornado Cash service. The site presents the page title "Tornado Cash Official | Private ETH, USDT & BNB Transactions," indicating an attempt to masquerade as the legitimate Tornado Cash platform. The domain resolves to 188.114.96.3, an address owned by Cloudflare, Inc. (AS13335) located in the United States, and is served behind Cloudflare with Browser Insights and HTTP/3 enabled. SSL is issued by Google Trust Services under the WE1 certificate, which provides a valid TLS handshake but does not attest to the legitimacy of the underlying content. Nameservers nola.ns.cloudflare.com and yoxall.ns.cloudflare.com further confirm reliance on Cloudflare’s DNS infrastructure.
Two of ninety‑three VirusTotal security vendors have flagged the domain, and it appears on three external blocklists. Independent blocklist providers PhishDestroy, MetaMask, and SEAL have already listed the domain as malicious, reinforcing the suspicion of phishing activity. The registrar listed is Spaceship, Inc., a known bulk registration service, and the Gridinsoft trust score is 0 out of 100, indicating an extremely low reputation.
The HTTP response is a 301 redirect, which may be used to forward victims to a credential‑stealing endpoint or to obscure the final landing page. While the exact payload or credential‑capture mechanism has not been publicly disclosed, the convergence of a brand‑specific page title, low trust scores, vendor detections, and blocklist entries provides sufficient evidence for defensive action.
Defenders should block both the domain and its resolved IP at perimeter firewalls and DNS filtering solutions. Endpoint protection suites should be updated to include the domain in their URL reputation feeds.
Datenabdeckung12 recorded checks
Erkenntnisse zur Netzwerksicherheit
Pipeline zur Reaktion auf Sicherheitsbedrohungen
Status der öffentlichen Sperrliste
Gespeicherte Aufnahme
Domain-Intelligenz
Technische DetailsDNS, SSL-SANs, Zeitstempel
ICANN OVERSIGHT
Akkreditierung und RAA-Kontext
Akkreditierung und RAA-Kontext
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Technologien · 3 identified
Performance monitoring tool that measures website speed from real users.
www.cloudflare.comWeb infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
VirusTotal-Analyse
Archivierte Beweise
Website-Performanceanalyse
Google PageSpeed Insights — mobile performance audit of tornadocashdao.com · checked Mar 2, 2026
Nachweise und externe BerichteIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Wenn Sie Kontoanmeldeinformationen, persönliche oder Zahlungsinformationen eingegeben oder eine Datei von dieser Domain heruntergeladen haben, ergreifen Sie sofort Maßnahmen. Nachfolgend finden Sie Ressourcen, die Ihnen helfen, den Vorfall zu melden und sich zu schützen.
Melden Sie sich bei Ihren örtlichen Behörden
Wählen Sie Ihr Land aus, um Offizielle Kontakte im Bereich Cyberkriminalität oder einen Beschwerdeentwurf erstellen → zu erhalten.