tismyuim[.]com
Análisis de phishing y seguridad de tismyuim.com
“Messenger”
tismyuim.com — Contenido no disponible (HTTP 502). Resumen de las pruebas: VirusTotal 4/91 (alphaMountain.ai, Fortinet, SOCRadar, Webroot); Spamhaus DBL_SPAM; CF Radar malicious; PhishDestroy score 71/100. Registrador: NiceNIC.
El análisis detallado de PhishDestroy AI se mantiene en inglés para conservar el registro forense original.
Evidence Analysis
Analysis of the domain tismyuim.com indicates it is actively serving a phishing page themed around a messaging service, as evidenced by the page title 'Messenger' and a confirmed HTTP 200 status. The domain resolves to the IP address 27.124.47.186, which is geolocated in Hong Kong and associated with Rackip Consultancy Pte. LTD. Infrastructure analysis reveals the domain was registered through NICENIC INTERNATIONAL GROUP CO., LIMITED and utilizes nameservers ns3.my-nddns.com and ns4.my-nddns.com. Security vendor detections on VirusTotal show 4 of 91 engines flagging the domain as malicious, and it appears on at least one security blocklist, including PhishDestroy. The SSL certificate is issued for 'Telegram' and a wildcard subdomain (*.local), which may suggest an attempt to lend legitimacy or obfuscate the true purpose of the site. The exact content and functionality of the phishing page remain unconfirmed, as no further technical indicators—such as phishing kit signatures, brand impersonation beyond the page title, or specific lure tactics—are available in the current data. Defenders should treat this domain as high-risk infrastructure due to its active status, confirmed malicious detections, and association with known phishing-supportive hosting providers. Network-level blocking of the domain and its resolving IP (27.124.47.186) is recommended, alongside monitoring for related domains registered through the same registrar or utilizing the same nameserver infrastructure. Further investigation into the SSL certificate issuer and any associated Telegram-themed artifacts may provide additional context for attribution or takedown efforts.
Cobertura de los datos13 recorded checks
Inteligencia de seguridad de red Registrar context
Proceso de respuesta ante amenazas Pipeline
Estado de la lista de bloqueados pública
Inteligencia de dominios
Detalles técnicosDNS, SAN de SSL, marcas de tiempo
ICANN OVERSIGHT
Acreditación y contexto RAA
Acreditación y contexto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Latest Classified Outcome 2026-08-09 04:27:04 UTC
Cruce de inteligencia de amenazas · source references
Análisis de VirusTotal
Datos y informes externosIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.