Zum Sicherheitsbericht springen
Checked 09.08.2026 Ref 882473D8

MALICIOUS — CRITICAL

telelfem[.]co

16 of 91 security engines flagged the domain; the latest stored check returned HTTP 200.

100/100 evidence score · Critical
VirusTotal
16/91
Blocklists
No stored match
Verfügbarkeit
Letzter bekanntermaßen aktiv · HTTP 200
Report / Add Evidence Appeal this listing
2026-07-15 05:03 UTCLetzter bekanntermaßen aktiv · HTTP 200

Do not enter credentials, seed phrases, payment details, or personal information on this domain.

⚠️
Diese Domain wurde als bösartig markiert.
Sicherheits-Engines melden eine Entdeckung: 16. Seien Sie äußerst vorsichtig – Geben Sie keine Anmeldeinformationen oder persönlichen Daten ein.
ABUSE NOTICE · 7D+ OPEN Outgoing abuse reports are recorded; the latest stored availability evidence still shows the domain reachable.
Notification and current-status evidence

The sent-report ledger records the first outgoing report at . The recorded recipient is abuse@rackip.com. The latest stored availability evidence still shows the domain reachable; 25 days has elapsed since the first outgoing report.

ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.

Elapsed since first report
25 days
Reports sent
1
Latest case ID
PD-20260715-2860C0
Current status
HTTP 200 at latest stored check
Jump to section
Berichtsübersicht

telelfem.co — Letzter bekanntermaßen aktiv (HTTP 200). Zusammenfassung der Beweislage: VirusTotal 16/91 (alphaMountain.ai, BitDefender, CyRadar, Emsisoft, Forcepoint ThreatSeeker); Spamhaus DBL_SPAM; PhishDestroy score 100/100. Registrar: NiceNIC.

Die ausführliche Analyse von PhishDestroy AI bleibt auf Englisch, damit der ursprüngliche forensische Bericht unverändert bleibt.

Evidence Digest

Ref 882473D8

telelfem.co is classified critical with an evidence score of 100/100. 16 of 91 security engines flagged the domain. Registered 10 Jun 2026 via NICENIC INTERNATIONAL GROUP CO., LIMITED, hosted on 27.124.47.186 (CTG Server Limited, HK). The latest stored check on 9 Aug 2026 returned HTTP 200 and includes a capture. 1 outgoing abuse report is recorded, most recently on 15 Jul 2026.

Stored generated summary (templated)cerebras · 15.07.2026

Retained for the record. This text repeats stored detection facts and is not presented as authored analysis.

The domain telelfem.co was registered on June 10, 2026 through NICENIC INTERNATIONAL GROUP CO., LIMITED and remains active as of the report date. DNS resolution points to the IPv4 address 27.124.47.186, hosted on nameservers ns3.my-ndns.com and ns4.my-ndns.com. The infrastructure suggests a recently created malicious site, consistent with the generic_phishing classification, but no public content or page metadata has been released for further analysis. Current intelligence does not provide details on the specific brand being impersonated, the phishing kit employed, or any observed payloads. Because the domain is actively resolving, defenders should assume it may be used in ongoing credential‑stealing campaigns. Recommended defensive actions include adding telelfem.co and its resolving IP address to block lists, monitoring outbound DNS queries for this domain, and reviewing recent email logs for indicators of phishing attempts referencing telelfem.co. Continuous observation of the domain’s DNS changes, registration details, and any future threat intelligence reports is advised to refine risk assessment as additional evidence becomes available.

VirusTotal
VirusTotal
16 det.
URLScan
URLScan
TLS-Zertifikat
Telegram / *.local
Alter
2 mo New
Beobachteter Status
Letzter bekanntermaßen aktiv 200
PhishDestroy
DestroyList
Gelistet
Reports Sent
1
Datenabdeckung12 recorded checks
VirusTotal 16 / 91 URLQuery checked — no detections recorded PhishStats nicht geprüft OTX no community references CF-Radar scan completed URLScan capture gespeicherter Bericht URLScan verdict Bewertung nicht verfügbar DNS-Sperren nicht geprüft TLS valid certificate, 766d WHOIS 2 mo old Screenshot 3 captures · 3 sources Weiterleitungskette nicht untersucht
Erkenntnisse zur Netzwerksicherheit Registrar context
Registrar context NiceNIC
Stored registration data identifies NICENIC INTERNATIONAL GROUP CO., LIMITED (IANA 3765) as the registrar. PhishDestroy maintains separate NiceNIC abuse-report research; registrar association is contextual and is not an independent detection for this domain.
NiceNIC Verdict Full Investigation

Pipeline zur Reaktion auf Sicherheitsbedrohungen

Entdeckung
Checks
Reports
Verfügbarkeit
10/11
Sent Report Recorded
Stored sent-report record for registrar NICENIC INTERNATIONAL GROUP CO., LIMITED, hosting provider, 3 abuse contacts
abuse@rackip.comabuse@nicenic.netabuse@ctgserver.net
15.07.2026

Status der öffentlichen Sperrliste

Gespeicherte Aufnahme

Domain-Intelligenz

Domain
Server / ASN nginx/1.18.0 (Ubuntu) · AS152194 CTG Server Limited
IP-Reputation abuse score 0/100 0 reports checked 15.07.2026
IP-Adresse 27.124.47.186 HK
StandortHK Sheung Wan, HK
NetzwerkAS152194 · Rackip Consultancy Pte. LTD
RegistrierungErstellt 10.06.2026 (59d · New) Expires 10.06.2027
HTTP-Status200
Technische DetailsDNS, SSL-SANs, Zeitstempel
Erstmals entdeckt15.07.2026
DOM Analysisanalyzed 15.07.2026score 88/100
IoC Extractionscanned 29.07.20260 wallet · 0 Telegram IoCs
Submitted URLhttp://telelfem.co/
Nameserverns3.my-ndns.comns4.my-ndns.com
TLS Fingerprint
TLS Observationvalid from 12.06.2026scanned 15.07.2026
Favicon Hash
Case ID
Seitentitel
Messenger
TLS-Zertifikat
Valid transport encryption · Ausgestellt von Telegram / *.local · valid for 766 days

Latest Classified Outcome 2026-08-09 02:45:02 UTC

Primary outcome Live content reason: Ordinary HTTP content served 90% confidence
Attribution source: Current Http Probe
Evidence layers Availability: Content serving Content: Content served at root DNS: Resolved Registration: Unknown
Latest HTTP observation Live content Ordinary HTTP content served 90% 2026-08-09 02:45:02 UTC
RDAP registration Unbekannt
Observed timeline last reachable: 2026-08-09 02:45:02 UTC last content: 2026-08-09 02:45:02 UTC
Availability, content, DNS and registration are independent evidence layers. NXDOMAIN, an unreachable origin or missing content alone does not prove registrar action. A registrar or provider is credited only when a direct technical marker identifies that actor. Report causality is shown separately.
Technologien · 3 identified
Ubuntu
Operating systems

Ubuntu is a free and open-source operating system on Linux for the enterprise server, desktop, cloud, and IoT.

www.ubuntu.com 100 % Konfidenz
Vue.js
JavaScript frameworks

Vue.js is an open-source model–view–viewmodel JavaScript framework for building user interfaces and single-page applications.

vuejs.org 100 % Konfidenz
Nginx
Web servers Reverse proxies

Nginx is a web server that can also be used as a reverse proxy, load balancer, mail proxy and HTTP cache.

nginx.org 100 % Konfidenz
Detected via Cloudflare Radar · Wappalyzer engine
Diese Domain melden Reichen Sie Beweismaterial ein und helfen Sie mit, andere zu schützen

VirusTotal-Analyse

16 / 91 Sicherheitsanbieter haben diese Domain markiert
View on VT
Last analyzed First positive detection Previous stored snapshot: 2 detections
alphaMountain.ai
BitDefender
CyRadar
Emsisoft
Forcepoint ThreatSeeker
Fortinet
G-Data
Gridinsoft
Kaspersky
LevelBlue
Lionic
Netcraft
SOCRadar
Sophos
VIPRE
Webroot
Nachweise und externe BerichteIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
If credentials were compromised, report immediately. Do not engage with recovery scammers.

Wenn Sie Kontoanmeldeinformationen, persönliche oder Zahlungsinformationen eingegeben oder eine Datei von dieser Domain heruntergeladen haben, ergreifen Sie sofort Maßnahmen. Nachfolgend finden Sie Ressourcen, die Ihnen helfen, den Vorfall zu melden und sich zu schützen.

Europol
Finden Sie den offiziellen Meldekanal für Ihr EU-Land
National police directory
Vorsicht vor Betrügern, die mit der Rückforderung von Geldern locken! Kriminelle nehmen unter Umständen erneut Kontakt zu Opfern auf und geben dabei vor, Ermittler, Anwälte oder Beitreibungsbeamte zu sein. Zahlen Sie keine Vorabgebühren und geben Sie keine Anmeldeinformationen weiter. Erfahren Sie mehr über Betrug im Zusammenhang mit Wiederaufbaumaßnahmen →

Melden Sie sich bei Ihren örtlichen Behörden

Wählen Sie Ihr Land aus, um Offizielle Kontakte im Bereich Cyberkriminalität oder einen Beschwerdeentwurf erstellen → zu erhalten.

97-Länder-Verzeichnis
KI-gestützter Entwurf – Vorfalldetails werden vom KI-Anbieter verarbeitet Überprüfen Sie es und reichen Sie es selbst ein
Diesen Bericht einbettenRead-only HTML widget
HTML · IFRAME

Diesen Bericht einbetten

Teilen Sie diese Bedrohungsinformationen auf Ihrer Website oder in Ihrem Blog

embed.html
<iframe
  src="https://phishdestroy.io/de/embed/domain/telelfem.co"
  title="PhishDestroy threat report for telelfem.co"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>