Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is abuse@ifastnet.com.
The latest stored availability evidence still shows the domain reachable; 22 days has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
app-tornadocash[.]rf[.]gd
Phishing and security check for app-tornadocash.rf.gd
Analysis of app-tornadocash.rf.gd indicates an active infrastructure that aligns with generic credential harvesting campaigns. The domain was registered on August 25, 2013 through Key-Systems GmbH and continues to resolve to the IPv4 address 185.27.134.164. Authoritative name servers are ns1.infinityfree.com and ns2.infinityfree.com, both associated with the free hosting provider InfinityFree. The domain remains live as of the report date, July 15, 2026. No public threat intelligence currently identifies a targeted brand or service, and the site content has not been examined, leaving the exact phishing lure uncertain. The absence of detections in the most recent VirusTotal scan (95 vendors) does not constitute validation of safety, as the scan result reflects only the lack of known signatures at the time of analysis. Defenders should treat the domain as suspicious, enforce outbound URL filtering to block connections to 185.27.134.164, and consider adding the domain to blocklists used by email gateways and web proxies. Continuous monitoring of DNS queries for the associated nameservers and periodic re‑scanning of the host are recommended to detect any future malicious payloads or changes in behavior.
Network Security Intelligence
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DigiCert UltraDNS | app-tornadocash.rf.gd |
malicious | Sinkholed |
Threat Response Pipeline
Public Blocklist Status
Technologies · 3 identified
Nginx is a web server that can also be used as a reverse proxy, load balancer, mail proxy and HTTP cache.
nginx.org 100% confidenceOpenResty is a web platform based on nginx which can run Lua scripts using its LuaJIT engine.
openresty.org 100% confidenceVirusTotal Analysis
Evidence & External Reports
PD-20260717-2DB257 Recipient: abuse@ifastnet.com Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive