phila[.]revenhtf[.]cc
“Florida Dept. of Revenue Florida Dept. of Revenue”
phila.revenhtf.cc — Contenu indisponible (HTTP 502). Usurpation de l'identité de la marque : Govphil. Résumé des preuves: VirusTotal 14/91 (ADMINUSLabs, BitDefender, CRDF, CyRadar, ESET); URLScan malicious verdict; PhishDestroy score 92/100. Bureau d’enregistrement: Dominet (HK).
L’analyse détaillée de PhishDestroy AI reste en anglais afin de préserver le relevé forensique original.
Analysis of the domain phila.revenhtf.cc, observed on July 29 2026, indicates that it was registered on September 16 2025 through Dominet (HK) Limited, a registrar known for hosting a variety of short‑lived domains. The domain resolves to the IPv4 address 170.106.160.91, which is currently associated with a hosting provider that has been referenced by multiple security feeds, but no further attribution such as ASN or country is provided in the available data. Reputation services have placed the domain on a single security blocklist, and the blocklist operator PhishDestroy actively blocks traffic to it, suggesting that at least one defensive network has identified malicious use.
VirusTotal observations show that 14 out of 91 scanning engines flag the domain as malicious, reinforcing the blocklist indication and providing independent corroboration of suspicious activity. The limited detection count and the presence on only one public blocklist imply that the campaign may be in an early or low‑volume phase, yet the consistent identification by multiple vendors demonstrates a non‑trivial risk. No public information about SSL certificates, HTTP response codes, page titles, or targeted brands has been published, leaving the exact content and lure technique of the site uncertain.
Defenders should therefore treat the domain as high‑confidence malicious, update intrusion‑detection signatures, enforce outbound filtering rules to block connections to 170.106.160.91, and add the domain to internal blocklists. Continuous monitoring of the registrar Dominet (HK) Limited and of any new sightings of the IP address is advised, as the infrastructure could be reused for additional campaigns. Until further forensic analysis of the hosted content is performed, the domain should be considered unsafe for end‑user interaction.
Renseignements sur la sécurité réseau
Processus de réponse aux menaces Pipeline
Statut de la liste de blocage publique
Capture enregistrée
Informations sur les domaines
Détails techniquesDNS, SAN SSL, horodatages
Analyse VirusTotal
Données factuelles et rapports externes
Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif