MALICIOUS — HIGH
thena[.]in
The domain thena.in was registered on February 21, 2026 through GoDaddy.com, LLC and is hosted on Amazon’s AS16509 network, resolving to IP address 76.223.67.189 located in the United States.
- VirusTotal
- 1/95
- Blocklists
- 1 · ScamSniffer
- Kullanılabilirlik
- İçerik kullanılamıyor · HTTP 502
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
thena.in — İçerik kullanılamıyor (HTTP 502). Marka kimliğine bürünme: Across. Kanıt özeti: VirusTotal 1/95 (SOCRadar); 1 external blocklist match (ScamSniffer); PhishDestroy score 58/100. Kayıt kuruluşu: GoDaddy.
Özgün adli kaydı korumak için aşağıdaki ayrıntılı PhishDestroy AI analizi İngilizce bırakılmıştır.
Evidence Analysis
thena.in SBA Loan Phishing Site – Elevated Risk
Security analysis of thena.in covers observed phishing indicators, infrastructure evidence, current status, and defensive guidance.
The domain thena.in was registered on February 21, 2026 through GoDaddy.com, LLC and is hosted on Amazon’s AS16509 network, resolving to IP address 76.223.67.189 located in the United States. No SSL certificate is presented, and the authoritative nameservers are ns69.domaincontrol.com and ns70.domaincontrol.com, both typical of GoDaddy’s DNS service. The site’s only observable content is the page title "SBA Loans Explained: Programs and Benefits | .Loans," indicating an attempt to lure victims with Small Business Administration loan information.
Threat intelligence sources have flagged the domain on two public blocklists, specifically PhishDestroy and ScamSniffer, and AlienVault OTX lists it in one pulse. VirusTotal analysis shows that one of ninety‑five security vendors flagged the domain, confirming at least one detection. The domain is currently offline, suggesting the operators have taken the site down, but the infrastructure remains observable.
Defenders should continue to monitor the IP 76.223.67.189 for any re‑use, enforce blocklist updates to include thena.in, and consider adding the domain to internal URL filtering policies. Because the site lacks TLS, any future activation would be vulnerable to interception, yet the presence of a known malicious page title and blocklist entries indicates a deliberate phishing campaign targeting individuals seeking SBA loan assistance. Further investigation is required to determine whether additional payloads or credential‑harvesting pages were ever served before the takedown.
Stored source results
Recorded verdicts and infrastructure observations for this domain.
Veri kapsamı12 recorded checks
Tehdit Müdahale Pipeline
Genel Engelleme Listesi Durumu
VirusTotal Analizi
Kanıtlar ve Dış RaporlarIndependent lookups and source reports
“The PhishDestroy system has identified this domain as a phishing threat, flagged both by our internal parser and reported by users. We also cross-reference with public databases and other antivirus systems.”
Victim safety and official reportingImmediate actions and verified reporting channels
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.