tether[.]beauty
“USDT 兌換合約”
tether.beauty — Контент недоступен (HTTP 502). Тип мошенничества: Crypto Scam. Сводка доказательств: VirusTotal 2/95 (CRDF, SOCRadar); PhishDestroy score 56/100. Регистратор: Gname.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
This domain is flagged for hosting a USDT crypto drainer, a specialized phishing threat designed to siphon cryptocurrency assets from victims under the guise of a legitimate Tether (USDT) exchange contract. The page title 'USDT 兌換合約' (USDT Exchange Contract) explicitly targets users expecting to engage in Tether transactions, a common tactic in crypto-related fraud. The elevated risk level is justified by the domain's technical indicators and confirmed malicious behavior, including the deployment of scripts to intercept and redirect digital assets. Analysis reveals multiple red flags in the domain's infrastructure. tether.beauty was registered on February 21, 2026, through Gname.com Pte. Ltd., a registrar frequently associated with high-risk domains. It resolves to the IP address 31.97.48.108, which has been linked to prior phishing campaigns. Detection metrics further confirm its malicious nature: 4 out of 95 security vendors on VirusTotal flag the domain, and it appears on at least one security blocklist, specifically PhishDestroy. The Gridinsoft trust score of 0/100 underscores its lack of credibility. Technologies detected on the domain include Ubuntu, Apache HTTP Server, Cloudflare, SweetAlert2, jsDelivr, jQuery, and cdnjs, which are often leveraged to obfuscate malicious activity or enhance the appearance of legitimacy. Mitigation against this crypto drainer requires heightened vigilance from cryptocurrency users. Individuals should verify the authenticity of any USDT-related website by cross-referencing official Tether communication channels or blockchain explorers before initiating transactions. Enabling multi-factor authentication (MFA) on cryptocurrency wallets and using hardware wallets for high-value transactions can reduce exposure to such threats. Network-level protections, such as DNS filtering or endpoint detection and response (EDR) solutions, should be configured to block known malicious IPs and domains, including 31.97.48.108 and tether.beauty. Users who suspect interaction with this domain should immediately revoke any connected wallet permissions and monitor their transaction history for unauthorized activity. Given the domain's current offline status, continued monitoring of related infrastructure is advised, as threat actors may redeploy similar tactics under new domains.
Данные сетевой безопасности
Процесс реагирования на угрозы
Статус в публичных блок-листах
Сохранённый снимок
Аналитика доменов
Технические сведенияDNS, SAN в протоколе SSL, временные метки
ICANN OVERSIGHT
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Технологии · 7 identified
Most widely used open-source HTTP server software.
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comFree public CDN for open-source projects, serving files from npm and GitHub.
Fast, small JavaScript library simplifying HTML manipulation, event handling, and Ajax.
Анализ VirusTotal
Архивные доказательства
Анализ производительности сайта
Google PageSpeed Insights — mobile performance audit of tether.beauty · checked Jun 27, 2026
Доказательства и внешние отчеты
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание