phila[.]revenuefe[.]cc
“502 Bad Gateway”
phila.revenuefe.cc — Non vérifié. Résumé des preuves: VirusTotal 11/91 (BitDefender, Chong Lua Dao, CyRadar, Forcepoint ThreatSeeker, Fortinet); PhishDestroy score 88/100. Bureau d’enregistrement: Dominet (HK).
L’analyse détaillée de PhishDestroy AI reste en anglais afin de préserver le relevé forensique original.
PhishDestroy identifies phila.revenuefe.cc as a phishing domain specifically targeting city tax refund applicants. This site mimics official Philadelphia revenue portals to trick users into submitting sensitive financial information, such as Social Security numbers, bank account details, and credit card numbers. The goal is to steal identities or drain funds by posing as a legitimate tax refund service. Users who land on this page may see fake login forms, urgent payment requests, or false refund status updates designed to create panic and prompt immediate action. This domain was flagged after security researchers observed its suspicious infrastructure, despite currently showing 0 detections out of 95 engines on VirusTotal. The site resolves to the IP address 43.166.241.242 and has since been taken offline, though similar domains may reappear. Records indicate the domain was registered through an offshore registrar, often used to obscure ownership and delay takedowns. The lack of initial detections highlights how new phishing campaigns can evade automated scanners until reported by users or researchers. If you visited phila.revenuefe.cc or entered any information, take immediate action to protect yourself. First, change passwords for any accounts linked to the site, especially financial or email accounts. Enable two-factor authentication wherever possible. Next, monitor your bank statements and credit reports for unauthorized transactions or new accounts opened in your name. Consider placing a fraud alert or credit freeze with major credit bureaus. Report the incident to the Federal Trade Commission at ReportFraud.ftc.gov and to your local police if financial loss occurred. Never respond to follow-up emails or calls claiming to help recover lost funds, as these are often secondary scams.
Processus de réponse aux menaces Pipeline
Statut de la liste de blocage publique
Capture enregistrée
Informations sur les domaines
Détails techniquesDNS, SAN SSL, horodatages
Analyse VirusTotal
Données factuelles et rapports externes
Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif