phila[.]revenue-kg[.]cc
“phila.revenue-kg.cc”
phila.revenue-kg.cc — Contenu indisponible. Résumé des preuves: VirusTotal 12/91 (ADMINUSLabs, Criminal IP, alphaMountain.ai, BitDefender, CRDF); PhishDestroy score 86/100. Bureau d’enregistrement: Dominet (HK).
L’analyse détaillée de PhishDestroy AI reste en anglais afin de préserver le relevé forensique original.
Analysis of the domain phila.revenue-kg.cc indicates an active generic phishing operation. The domain was registered through Dominet (HK) Limited on September 16 2025 and currently resolves to the IPv4 address 43.130.77.166. VirusTotal reports that 12 of 91 scanned security vendors have flagged the domain as malicious, suggesting a moderate detection consensus. The domain is listed on a single external blocklist and is explicitly blocked by the PhishDestroy service, reinforcing its classification as a phishing threat.
Infrastructure assessment shows the hosting IP 43.130.77.166 is not associated with any known reputable content delivery networks or cloud providers, and no public SSL certificate information is available, which is typical for short‑lived phishing sites. No Safe Browsing, Open Threat Exchange, or additional trust‑score data were observed for this domain, leaving those vectors unverified. The page title and any brand‑specific content have not been disclosed, so the exact impersonated entity cannot be confirmed at this time.
Given the limited but concrete evidence—registration details, IP address, multi‑vendor detection, blocklist inclusion, and PhishDestroy block—the domain should be treated as high‑confidence malicious. Defensive recommendations include adding the domain to local deny lists, configuring web proxies to block HTTP(S) requests to the address, updating intrusion‑prevention signatures that reference the hosting IP, and monitoring DNS logs for queries to phila.revenue-kg.cc. Continuous re‑evaluation is advised as additional telemetry, such as SSL certificates or page content, becomes available.
Renseignements sur la sécurité réseau
Processus de réponse aux menaces Pipeline
Statut de la liste de blocage publique
Capture enregistrée
Informations sur les domaines
Détails techniquesDNS, SAN SSL, horodatages
Analyse VirusTotal
Données factuelles et rapports externes
Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif