Skip to security report
⚠️
This domain has been flagged as malicious
Security engines reporting a detection: 2. Exercise extreme caution — do not enter credentials or personal information.
Domain security and threat intelligence

tether[.]beauty

“USDT 兌換合約”

Threat verdict High 56/100 evidence score
Availability Content unavailable Content was unavailable in the latest observation
VirusTotal detections: 2/95 Scam type: Crypto Scam
Feb 3, 2026
Evidence Summary
HIGH
Ref
2E14298F
Score
56/100

This domain is flagged for hosting a USDT crypto drainer, a specialized phishing threat designed to siphon cryptocurrency assets from victims under the guise of a legitimate Tether (USDT) exchange contract. The page title 'USDT 兌換合約' (USDT Exchange Contract) explicitly targets users expecting to engage in Tether transactions, a common tactic in crypto-related fraud. The elevated risk level is justified by the domain's technical indicators and confirmed malicious behavior, including the deployment of scripts to intercept and redirect digital assets. Analysis reveals multiple red flags in the domain's infrastructure. tether.beauty was registered on February 21, 2026, through Gname.com Pte. Ltd., a registrar frequently associated with high-risk domains. It resolves to the IP address 31.97.48.108, which has been linked to prior phishing campaigns. Detection metrics further confirm its malicious nature: 4 out of 95 security vendors on VirusTotal flag the domain, and it appears on at least one security blocklist, specifically PhishDestroy. The Gridinsoft trust score of 0/100 underscores its lack of credibility. Technologies detected on the domain include Ubuntu, Apache HTTP Server, Cloudflare, SweetAlert2, jsDelivr, jQuery, and cdnjs, which are often leveraged to obfuscate malicious activity or enhance the appearance of legitimacy. Mitigation against this crypto drainer requires heightened vigilance from cryptocurrency users. Individuals should verify the authenticity of any USDT-related website by cross-referencing official Tether communication channels or blockchain explorers before initiating transactions. Enabling multi-factor authentication (MFA) on cryptocurrency wallets and using hardware wallets for high-value transactions can reduce exposure to such threats. Network-level protections, such as DNS filtering or endpoint detection and response (EDR) solutions, should be configured to block known malicious IPs and domains, including 31.97.48.108 and tether.beauty. Users who suspect interaction with this domain should immediately revoke any connected wallet permissions and monitor their transaction history for unauthorized activity. Given the domain's current offline status, continued monitoring of related infrastructure is advised, as threat actors may redeploy similar tactics under new domains.

VirusTotal
VirusTotal
2 det.
URLScan
URLScan
TLS Certificate
Expired or unverified
Observed status
Content unavailable 502
PhishDestroy
DestroyList
Listed
Data coverage VirusTotal 2 / 95 URLQuery not checked PhishStats not checked OTX no community references CF Radar scan completed URLScan capture stored report URLScan verdict verdict unavailable DNS blocks 14 checked — no blocks TLS Expired or unverified WHOIS not parsed Screenshot external capture Redirect chain not probed
Network Security Intelligence
SSL Certificate Invalid
SSL certificate is invalid or expired. Issuer:

Threat Response Pipeline

Discovery
Checks
Reports
Availability
13/14

Public Blocklist Status

Stored Capture

Page Title
USDT 兌換合約
TLS Certificate
Expired or unverified · Issued by Let's Encrypt / E8

Domain Intelligence

Domain
Server / ASN Apache/2.4.58 (Ubuntu) · AS47583 Hostinger International Limited
IP Reputation abuse score 0/100 0 reports checked Jun 16, 2026
IP Address 31.97.48.108 ID
GeoID Jakarta, ID
NetworkAS47583 · Hostinger International Limited
RegistrationExpires Jun 18, 2026
HTTP Status502 Error
Time to First Unavailability 40 days
What we count Elapsed time from the first stored abuse report to the first observation that the content was unavailable. This does not establish the cause.
What each report contains Stored outgoing-report records may reference evidence available at the time, such as vendor verdicts, registration data, hosting details, classifications, or screenshots. This page does not infer the exact payload delivered, receipt, acknowledgement, or action by a recipient.
Technical detailsDNS, SSL SANs, timestamps
First DetectedFeb 3, 2026
DOM Analysisanalyzed Jul 29, 2026score 0/100
IoC Extractionscanned Aug 2, 20260 wallet · 0 Telegram IoCs
Submitted URLhttps://tether.beauty/
Nameserversb6.share-dns.net
TLS Fingerprint
TLS Observationvalid from Mar 10, 2026scanned Mar 15, 2026
ICANN OVERSIGHT

Accreditation and RAA context

Registrar accreditation and DNS abuse obligations

For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.

Accreditation is a contract, not a safety certification.

RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.

Accountability draft Nothing is sent automatically.
Technologies · 7 identified
Ubuntu
Apache HTTP Server
Web servers

Most widely used open-source HTTP server software.

Cloudflare
CDN

Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.

www.cloudflare.com
SweetAlert2
J
jsDelivr
CDN

Free public CDN for open-source projects, serving files from npm and GitHub.

jQuery
JavaScript libraries

Fast, small JavaScript library simplifying HTML manipulation, event handling, and Ajax.

cdnjs
Detected via Cloudflare Radar · Wappalyzer engine
Report This Domain Submit evidence & help protect others

VirusTotal Analysis

2 / 95 security vendors flagged this domain
View on VT
Last analyzed
CRDF
SOCRadar

Archived Evidence

Wayback Machine Snapshot
A historical snapshot is available for evidence review
View Archive
Site Performance Analysis

Google PageSpeed Insights — mobile performance audit of tether.beauty · checked Jun 27, 2026

84
Needs Work
Performance
FCP
1.99s
First Contentful Paint
LCP
3.27s
Largest Contentful Paint
CLS
0
Cumulative Layout Shift
TBT
0ms
Total Blocking Time
SI
6.91s
Speed Index
Powered by Google PageSpeed Insights · Mobile strategy · Scores: 90-100 Good 50-89 Needs Work 0-49 Poor

Evidence & External Reports

Were You Affected by This Site?

If credentials were compromised, report immediately. Do not engage with recovery scammers.

If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.

Europol
Find the official reporting channel for your EU country
National police directory
Beware of recovery scammers! Recovery scammers may pose as investigators, lawyers, or tracing services. Do not pay upfront fees or disclose credentials. Learn more about recovery fraud →

Report to Your Local Authorities

Select your country to get official cybercrime contacts, or create a complaint draft →.

97-country directory
Template-based draft • optional AI wording assistance requires separate consent Review and submit it yourself

Check Any Domain

Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence

Scan Now

Report Phishing

Submit suspicious domains to our threat database — protect the community

Report

Live Threat Feed

Recent phishing reports and observed availability changes

Monitor

Stay Informed, Stay Safe

Monitor live threats or contest this listing if you believe it's a false positive

Live Threat Feed Appeal This Listing
HTML · IFRAME

Embed This Report

Share this threat intelligence on your website or blog

embed.html
<iframe
  src="https://phishdestroy.io/embed/domain/tether.beauty"
  title="PhishDestroy threat report for tether.beauty"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>

A Very Sincere Thank-You Note

Satirical draft generator

Recipient
Fee context

Satirical draft. Fee figures are estimates; exact attribution to this domain is not claimed.