الانتقال إلى تقرير الأمان
⚠️
تم الإبلاغ عن هذا النطاق باعتباره ضارًّا
محركات الأمان التي تبلغ عن اكتشاف: 6. توخي الحذر الشديد — لا تدخل بيانات الاعتماد أو المعلومات الشخصية.
أمن المجال وذكاء التهديدات

phila[.]revenuefr[.]cc

“502 Bad Gateway”

حكم التهديد حرجة 78/100 درجة الأدلة
التوفر لم يتم التحقق منها لم يتم التحقق من إمكانية الوصول الحالية
اكتشافات VirusTotal: 6/91 نوع الاحتيال: Generic Phishing
13/06/2026
ملخص التقرير

phila.revenuefr.cc — لم يتم التحقق منها. نوع الاحتيال: Generic Phishing. ملخص الأدلة: VirusTotal 6/91 (Chong Lua Dao, Forcepoint ThreatSeeker, Fortinet, Gridinsoft, SOCRadar); PhishDestroy score 78/100. مسجّل النطاق: Dominet (HK).

يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.

ملخص الأدلة
حرج
المرجع
365B8361
الدرجة
78/100

PhishDestroy identifies phila.revenuefr.cc as a high-risk phishing domain specifically designed to impersonate an official IRS tax filing portal. This domain was flagged for hosting a fake login page that harvests taxpayer credentials, Social Security numbers, and financial details under the guise of processing tax refunds or resolving audit notices. The threat type is classified as a government impersonation phishing scam, which is particularly dangerous due to its potential to facilitate identity theft, tax fraud, and unauthorized access to IRS accounts. This domain currently resolves to the IP address 43.166.241.242, which is hosted on infrastructure known for supporting phishing campaigns. As of the latest scan, VirusTotal reports 0 detections out of 95 security engines, indicating that the domain has not yet been widely flagged by antivirus or threat intelligence platforms. The domain is registered through an offshore registrar, which often complicates takedown efforts due to less stringent abuse policies. No creation date is publicly available, but the domain's structure—using 'phila' to mimic the Philadelphia IRS office and 'revenuefr' to suggest a revenue or financial portal—strongly suggests malicious intent. The domain is not currently listed on major blocklists, and its trust scores remain neutral due to the lack of prior detections. However, its recent takedown status indicates that hosting providers or registrars have already intervened, likely due to abuse reports. Users who may have interacted with phila.revenuefr.cc should immediately take steps to mitigate potential damage. First, do not enter any additional information or attempt to log in to the site. If credentials were submitted, change passwords for IRS.gov and any other accounts using the same login details. Enable multi-factor authentication (MFA) on all financial and government accounts to prevent unauthorized access. Monitor bank statements, credit reports, and IRS communications for signs of fraudulent activity, such as unexpected tax filings or refunds. Report the incident to the IRS Identity Theft Protection Unit and file a complaint with the Federal Trade Commission (FTC) at IdentityTheft.gov. For organizations or individuals who encountered this domain, block the IP address 43.166.241.242 and the domain itself at the firewall or DNS level to prevent further exposure. Always verify the legitimacy of tax-related websites by ensuring they use the official IRS.gov domain and look for HTTPS encryption and valid security certificates.

VirusTotal
VirusTotal
6 det.
شهادة TLS
منتهية الصلاحية أو غير متحقق منها -288d
العمر
2 mo New
الحالة المرصودة
لم يتم التحقق منها
PhishDestroy
قائمة الإتلاف
مُدرج
نطاق تغطية البيانات VirusTotal 6 / 91 URLQuery لم يتم التحقق منها PhishStats لم يتم التحقق منها OTX no community references رادار CF no data URLScan capture not submitted URLScan verdict التقييم غير متاح حجب عناوين DNS لم يتم التحقق منها TLS منتهية الصلاحية أو غير متحقق منها WHOIS 2 mo old لقطة شاشة لقطة خارجية سلسلة إعادة التوجيه لم يتم التحقيق فيها

مسار الاستجابة للتهديدات Pipeline

الاكتشاف
Checks
Reports
التوفر
6/8

حالة قوائم الحظر العامة

لقطة محفوظة

عنوان الصفحة
502 Bad Gateway
شهادة TLS
منتهية الصلاحية أو غير متحقق منها · صادرة عن DigiCert Inc / Encryption Everywhere DV TLS CA - G2

معلومات النطاق

النطاق
الخادم / ASN nginx/1.14.1 · AS132203 Tencent Building, Kejizhongyi Avenue
سمعة عنوان IP abuse score 0/100 0 reports checked 12/08/2026
Registrar (base domain) Dominet (HK) HK(HK)
عنوان IP 43.166.241.242 US
الموقع الجغرافيUS Ashburn, US
الشبكةAS132203 · Aceville Pte.ltd
Registration (base domain)revenuefr.cc · تم إنشاؤه 12/06/2026 (67d · New)
التفاصيل الفنيةDNS، أسماء المجال البديلة (SAN) في بروتوكول SSL، الطوابع الزمنية
تاريخ أول اكتشاف13/06/2026
خوادم الأسماءns8.alidns.com
TLS Fingerprint
TLS Observationvalid from 04/11/2024scanned 26/06/2026
TLS SAN Domainscallback.admile.xyz
الإبلاغ عن هذا النطاق أرسل الأدلة وساعد في حماية الآخرين

تحليل VirusTotal

6 / قام موردو الأمان 91 بوضع علامة على هذا المجال
View on VT
Last analyzed
Chong Lua Dao
Forcepoint ThreatSeeker
Fortinet
Gridinsoft
SOCRadar
Webroot

الأدلة والتقارير الخارجية

نظام أسماء النطاقات (DNS) والشبكات
تحسين محركات البحث (SEO) والنطاقات

هل تأثرت بهذا الموقع؟

If credentials were compromised, report immediately. Do not engage with recovery scammers.

إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.

اليوروبول
ابحث عن قناة التقارير الرسمية لبلدك في الاتحاد الأوروبي
National police directory
احذروا من المحتالين الذين يزعمون أنهم يساعدون في استرداد الأموال! قد يتصل المجرمون بالضحايا مرة أخرى بينما يتظاهرون بأنهم محققون أو محامون أو وكلاء استرداد. لا تدفع رسومًا مقدمة أو تشارك بيانات الاعتماد. تعرف على المزيد حول الاحتيال في مجال التعافي →

أبلغ السلطات المحلية

حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.

دليل 97 دولة
المسودة بمساعدة الذكاء الاصطناعي - تتم معالجة تفاصيل الحادث بواسطة موفر الذكاء الاصطناعي قم بمراجعتها وتقديمها بنفسك

تحقق من أي نطاق

تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة

امسح الآن

الإبلاغ عن محاولة تصيد احتيالي

أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع

إبلاغ

تحديثات فورية حول التهديدات

تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة

مراقبة

ابقَ على اطلاع، وابقَ آمنًا

راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب

تحديثات فورية حول التهديدات الاعتراض على هذا الإعلان
HTML · IFRAME

تضمين هذا التقرير

شارك هذه المعلومات الاستخباراتية المتعلقة بالتهديدات على موقعك الإلكتروني أو مدونتك

embed.html
<iframe
  src="https://phishdestroy.io/ar/embed/domain/phila.revenuefr.cc"
  title="PhishDestroy threat report for phila.revenuefr.cc"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>