tetherdefai[.]net
“Cierpliwości...”
Riepilogo delle prove
Analysis of the domain tetherdefai.net indicates it is associated with a confirmed crypto scam, as classified by security vendors and blocklists. The domain was registered on December 16, 2025, through NameCheap, Inc., and is currently offline, having been taken down following detection by PhishDestroy. Infrastructure analysis reveals the domain resolved to the IP address 104.21.20.77, which is hosted on Cloudflare's network (AS13335) in the United States. The domain utilized Cloudflare nameservers (carioca.ns.cloudflare.com and cash.ns.cloudflare.com), a common tactic to obscure hosting details and evade takedowns. No SSL certificate was detected, increasing the likelihood of unencrypted communications, a red flag for fraudulent sites.
The page title 'Cierpliwości...' (translated from Polish as 'Patience...') suggests the site may have targeted users with a delay tactic, a common social engineering technique in crypto scams to create a false sense of legitimacy or processing time. Gridinsoft assigned a trust score of 0/100, reinforcing the domain's high-risk status. While only one of 93 security vendors on VirusTotal flagged the domain, this does not diminish its threat level, as detection rates can vary based on timing and vendor focus. The domain appears on at least one security blocklist, further corroborating its malicious classification.
Defenders should treat this domain as a confirmed crypto scam and prioritize blocking it at the DNS and network levels. Given its Cloudflare-hosted infrastructure, monitoring for re-registration or similar domains using the same nameservers or IP ranges is recommended. The absence of SSL and the use of a generic page title underscore the need for caution, as these are hallmarks of low-effort but effective phishing and scam operations. No specific brand impersonation was identified in the available data, but the crypto scam classification indicates financial fraud intent.
Data Coverage
Pipeline di risposta alle minacce
Copertura delle blocklist
10 fonti esterne monitorate · snapshot del 11/08/2026
10 fonti esterne monitorate Nessuna corrispondenza
Cronologia del rilevamento
-
Cloudflare Radar
Scansione Cloudflare Radar archiviata · Apri scansione
Acquisizione salvata
Analisi dei domini
Dettagli tecniciDNS, nomi TLS e date
ICANN OVERSIGHT
Accreditamento e contesto RAA
Accreditamento e contesto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Analisi di VirusTotal
Questo sito ti ha influenzato in qualche modo?
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.
Verifica qualsiasi dominio
Analisi delle minacce utilizzando blocklist archiviate, WHOIS, DNS e prove di scansione pubblica
Scansiona oraSegnala un tentativo di phishing
Segnala i domini sospetti al nostro database delle minacce — proteggi la comunità
SegnalaFeed in tempo reale sulle minacce
Segnalazioni recenti di phishing e modifiche osservate della disponibilità
MonitoraRimani informato, rimani al sicuro
Controlla le minacce in tempo reale oppure contesta questa segnalazione se ritieni che si tratti di un falso positivo