phila[.]revenhtf[.]cc
“Florida Dept. of Revenue Florida Dept. of Revenue”
phila.revenhtf.cc — Contenido no disponible (HTTP 502). Suplantación de marca: Govphil. Resumen de las pruebas: VirusTotal 14/91 (ADMINUSLabs, BitDefender, CRDF, CyRadar, ESET); URLScan malicious verdict; PhishDestroy score 92/100. Registrador: Dominet (HK).
El análisis detallado de PhishDestroy AI se mantiene en inglés para conservar el registro forense original.
Analysis of the domain phila.revenhtf.cc, observed on July 29 2026, indicates that it was registered on September 16 2025 through Dominet (HK) Limited, a registrar known for hosting a variety of short‑lived domains. The domain resolves to the IPv4 address 170.106.160.91, which is currently associated with a hosting provider that has been referenced by multiple security feeds, but no further attribution such as ASN or country is provided in the available data. Reputation services have placed the domain on a single security blocklist, and the blocklist operator PhishDestroy actively blocks traffic to it, suggesting that at least one defensive network has identified malicious use.
VirusTotal observations show that 14 out of 91 scanning engines flag the domain as malicious, reinforcing the blocklist indication and providing independent corroboration of suspicious activity. The limited detection count and the presence on only one public blocklist imply that the campaign may be in an early or low‑volume phase, yet the consistent identification by multiple vendors demonstrates a non‑trivial risk. No public information about SSL certificates, HTTP response codes, page titles, or targeted brands has been published, leaving the exact content and lure technique of the site uncertain.
Defenders should therefore treat the domain as high‑confidence malicious, update intrusion‑detection signatures, enforce outbound filtering rules to block connections to 170.106.160.91, and add the domain to internal blocklists. Continuous monitoring of the registrar Dominet (HK) Limited and of any new sightings of the IP address is advised, as the infrastructure could be reused for additional campaigns. Until further forensic analysis of the hosted content is performed, the domain should be considered unsafe for end‑user interaction.
Inteligencia de seguridad de red
Proceso de respuesta ante amenazas Pipeline
Estado de la lista de bloqueados pública
Captura guardada
Inteligencia de dominios
Detalles técnicosDNS, SAN de SSL, marcas de tiempo
Análisis de VirusTotal
Datos y informes externos
¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.