phila[.]revenue-gi[.]cc
“Florida Dept. of Revenue Florida Dept. of Revenue”
phila.revenue-gi.cc — Contenu indisponible. Usurpation de l'identité de la marque : Govphil. Résumé des preuves: VirusTotal 14/91 (ADMINUSLabs, BitDefender, CRDF, CyRadar, ESET); URLScan malicious verdict; PhishDestroy score 92/100. Bureau d’enregistrement: Dominet (HK).
L’analyse détaillée de PhishDestroy AI reste en anglais afin de préserver le relevé forensique original.
Analysis as of July 29, 2026 indicates that the domain phila.revenue-gi.cc is actively being used for phishing operations and is classified with an elevated risk level. The domain was registered on September 15, 2025 through Dominet (HK) Limited, and DNS resolution points to the single IPv4 address 43.130.77.166. VirusTotal has recorded detections from 14 of 91 security vendors, demonstrating a measurable consensus among scanning engines that the domain is malicious.
The domain appears on one external security blocklist and has been explicitly blocked by the PhishDestroy feed, confirming that at least one reputable anti‑phishing service is already filtering traffic to it. No further infrastructure details such as ASN, hosting provider, or geographic location are disclosed in the available intelligence, and the current HTTP response code, TLS certificate status, or page title have not been published, leaving those aspects of the site’s surface unknown. Given the confirmed phishing classification, the elevated risk rating, and the existing vendor detections, defenders should add phila.revenue-gi.cc to deny‑list configurations at network perimeters, proxy servers, and endpoint protection solutions.
Continuous monitoring of the associated IP address 43.130.77.166 is advised, as any change in hosting or additional sub‑domains could indicate campaign expansion. Organizations should also ensure that any user‑facing authentication portals are protected by multi‑factor authentication and that employees are educated on the risks of unsolicited credential requests, as the domain’s intent aligns with credential harvesting.
Renseignements sur la sécurité réseau
Processus de réponse aux menaces Pipeline
Statut de la liste de blocage publique
Capture enregistrée
Informations sur les domaines
Détails techniquesDNS, SAN SSL, horodatages
Analyse VirusTotal
Données factuelles et rapports externes
Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif