tdccpmeme[.]pw
“$TDCCP”
tdccpmeme.pw — Non vérifié. Résumé des preuves: VirusTotal 1/95 (alphaMountain.ai); PhishDestroy score 71/100. Bureau d’enregistrement: Go Daddy.
L’analyse détaillée de PhishDestroy AI reste en anglais afin de préserver le relevé forensique original.
Analysis of tdccpmeme.pw shows a recent registration (February 21, 2026) through Go Daddy, LLC and immediate deployment of a site hosted behind Cloudflare (AS13335) at IP address 104.21.8.235. The domain resolves to this Cloudflare‑backed IP, utilizes Cloudflare name servers (alla.ns.cloudflare.com, emerson.ns.cloudflare.com), and presents an SSL certificate issued by Google Trust Services / WE1, indicating a valid TLS configuration. HTTP responses return status code 200 and the page title is captured as "$TDCCP", confirming that the site was reachable before being taken offline. Technical fingerprinting reveals the presence of Vercel, HSTS, Google Analytics, and HTTP/3, all typical of modern web services but also common in malicious infrastructure leveraging reputable platforms to evade detection.
The domain is listed on a single security blocklist and has been specifically flagged by PhishDestroy, reinforcing its classification as a generic phishing vector. VirusTotal scans report that one of ninety‑five security vendors identified the domain as malicious, providing a modest but notable detection signal. Independent reputation scoring from Gridinsoft assigns a trust score of 39 out of 100, reflecting low confidence in the domain's legitimacy.
Although the site is currently offline, the elevated risk rating remains justified given the combination of recent creation, rapid deployment, legitimate‑looking TLS, and confirmed detection across multiple threat intelligence sources. Defenders should continue to block tdccpmeme.pw at perimeter controls, monitor DNS queries for the associated Cloudflare IP, and update any web filtering or email security policies to include this indicator. Ongoing vigilance is advised in case the domain is reactivated or similar patterns emerge in other newly registered .pw zones.
Processus de réponse aux menaces Pipeline
Statut de la liste de blocage publique
Technologies · 5 identified
Vercel is a cloud platform for static frontends and serverless functions.
vercel.com Confiance à 100 %HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org Confiance à 100 %Google Analytics is a free web analytics service that tracks and reports website traffic.
google.com Confiance à 100 %Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com Confiance à 100 %HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org Confiance à 100 %Analyse VirusTotal
Analyse de la configuration du site
Données factuelles et rapports externes
“We, the undersigned investors, are writing to formally lodge a complaint against Action Action Action LLC , a company registered in New York, located at 87-10 51 Ave, Rm 2P, Elmhurst, NY, 11373, and its operational team, led by Mr. Qi Fuwei (online alias: William Wang), for alleged fraudulent activities related to the issuance and trading of the $TDCCP meme coin on a public blockchain. The website is https://tdccpmeme.pw/. We believe these actions have caused significant financial harm to”
Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif