tetherdefai[.]net
“Cierpliwości...”
tetherdefai.net — Conteúdo indisponível (HTTP 502). Tipo de golpe: Crypto Scam. Resumo das evidências: VirusTotal 1/93 (SOCRadar); PhishDestroy score 55/100. Registrador: NameCheap.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
Analysis of the domain tetherdefai.net indicates it is associated with a confirmed crypto scam, as classified by security vendors and blocklists. The domain was registered on December 16, 2025, through NameCheap, Inc., and is currently offline, having been taken down following detection by PhishDestroy. Infrastructure analysis reveals the domain resolved to the IP address 104.21.20.77, which is hosted on Cloudflare's network (AS13335) in the United States. The domain utilized Cloudflare nameservers (carioca.ns.cloudflare.com and cash.ns.cloudflare.com), a common tactic to obscure hosting details and evade takedowns. No SSL certificate was detected, increasing the likelihood of unencrypted communications, a red flag for fraudulent sites.
The page title 'Cierpliwości...' (translated from Polish as 'Patience...') suggests the site may have targeted users with a delay tactic, a common social engineering technique in crypto scams to create a false sense of legitimacy or processing time. Gridinsoft assigned a trust score of 0/100, reinforcing the domain's high-risk status. While only one of 93 security vendors on VirusTotal flagged the domain, this does not diminish its threat level, as detection rates can vary based on timing and vendor focus. The domain appears on at least one security blocklist, further corroborating its malicious classification.
Defenders should treat this domain as a confirmed crypto scam and prioritize blocking it at the DNS and network levels. Given its Cloudflare-hosted infrastructure, monitoring for re-registration or similar domains using the same nameservers or IP ranges is recommended. The absence of SSL and the use of a generic page title underscore the need for caution, as these are hallmarks of low-effort but effective phishing and scam operations. No specific brand impersonation was identified in the available data, but the crypto scam classification indicates financial fraud intent.
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Captura armazenada
Inteligência de Domínios
Detalhes técnicosDNS, SANs do SSL, carimbos de data e hora
ICANN OVERSIGHT
Credenciamento e contexto RAA
Credenciamento e contexto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Análise do VirusTotal
Evidências e relatórios externos
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo