tether-confirmation[.]com
tether-confirmation.com की फ़िशिंग और सुरक्षा जाँच
“Wallet Check - AML Check”
tether-confirmation.com — सामग्री अनुपलब्ध (HTTP 502). ब्रांड प्रतिरूपण: Tron; घोटाले का प्रकार: Crypto Scam. साक्ष्य सारांश: VirusTotal 6/93 (CyRadar, G-Data, Gridinsoft, Kaspersky, Sophos); URLQuery 2 det.; 1 external blocklist match (ScamSniffer); PhishDestroy score 72/100. रजिस्ट्रार: Realtime.
मूल फॉरेंसिक रिकॉर्ड सुरक्षित रखने के लिए नीचे का विस्तृत PhishDestroy AI विश्लेषण अंग्रेज़ी में रखा गया है।
tether-confirmation.com was registered on 21 February 2026 through Realtime Register B.V. The domain resolves to the Cloudflare address 172.67.181.4, which belongs to AS13335 Cloudflare, Inc. and is geolocated in the United States. The zone is served by the Cloudflare nameservers lana.ns.cloudflare.com and paul.ns.cloudflare.com, and no TLS certificate was observed, indicating that HTTPS is not offered. The site presented the page title “Wallet Check – AML Check” and was classified as a crypto‑scam impersonating the Tron brand. VirusTotal records show that six of ninety‑three scanning engines flagged the domain, and the domain appears on two independent blocklists, PhishDestroy and ScamSniffer.
Gridinsoft assigned a trust score of zero out of one hundred, reinforcing the malicious assessment. The domain’s current status is offline, which prevents further live analysis, and no additional payload or infrastructure details have been released. Defenders should continue to block the IP address 172.67.181.4 and the associated Cloudflare host, add tether‑confirmation.com to internal blacklists, and monitor for any re‑hosting of the same page title or similar brand‑targeted content.
Because the domain was hosted on a shared Cloudflare edge, future clones may appear under different subdomains but retain the same ASN and registrar pattern. Continuous observation of the registrar Realtime Register B.V. and the two blocklists is recommended to detect possible re‑registration attempts. Until the domain reappears, the existing evidence suggests a high‑confidence malicious indicator tied to a Tron impersonation campaign.
धमकी प्रतिक्रिया पाइपलाइन
सार्वजनिक ब्लॉकलिस्ट स्थिति
सहेजा गया कैप्चर
डोमेन इंटेलिजेंस
तकनीकी विवरणडीएनएस, एसएसएल एसएएन, टाइमस्टैम्प
ICANN OVERSIGHT
प्रत्यायन और आरएए संदर्भ
प्रत्यायन और आरएए संदर्भ
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
फॉरेंसिक इंटेलिजेंस
वायरसटोटल विश्लेषण
संग्रहीत साक्ष्य
साक्ष्य और बाहरी रिपोर्टें
PD-20260219-3E1613 Recipient: rtr-security-threats@realtimeregister.com क्या आप इस साइट से प्रभावित हुए?
यदि आपने खाता क्रेडेंशियल, व्यक्तिगत या भुगतान जानकारी दर्ज की है, या इस डोमेन से कोई फ़ाइल डाउनलोड की है, तो तुरंत कार्रवाई करें। घटना की रिपोर्ट करने और अपनी सुरक्षा करने में आपकी सहायता के लिए नीचे संसाधन दिए गए हैं।
अपने स्थानीय अधिकारियों को रिपोर्ट करें
आधिकारिक साइबर अपराध संपर्क, या एक शिकायत ड्राफ्ट बनाएं → प्राप्त करने के लिए अपना देश चुनें।
किसी भी डोमेन की जाँच करें
संग्रहीत ब्लॉकलिस्ट, WHOIS, DNS और सार्वजनिक स्कैन साक्ष्य का उपयोग करके खतरे का विश्लेषण
अभी स्कैन करेंफ़िशिंग की रिपोर्ट करें
संदिग्ध डोमेन हमारे थ्रेट डेटाबेस में जमा करें — समुदाय की सुरक्षा करें
रिपोर्ट करेंसीधा खतरा फीड
हाल की फ़िशिंग रिपोर्टें और उपलब्धता में परिवर्तन देखे गए
निगरानी करेंजानकारी में रहें, सुरक्षित रहें
लाइव खतरों की निगरानी करें या यदि आपको लगता है कि यह एक गलत सकारात्मक है तो इस लिस्टिंग को चुनौती दें।