phila[.]revenuefr[.]cc
“502 Bad Gateway”
phila.revenuefr.cc — Belum terverifikasi. Jenis penipuan: Generic Phishing. Ringkasan bukti: VirusTotal 6/91 (Chong Lua Dao, Forcepoint ThreatSeeker, Fortinet, Gridinsoft, SOCRadar); PhishDestroy score 78/100. Registrar: Dominet (HK).
Analisis terperinci PhishDestroy AI di bawah tetap berbahasa Inggris untuk menjaga catatan forensik asli.
PhishDestroy identifies phila.revenuefr.cc as a high-risk phishing domain specifically designed to impersonate an official IRS tax filing portal. This domain was flagged for hosting a fake login page that harvests taxpayer credentials, Social Security numbers, and financial details under the guise of processing tax refunds or resolving audit notices. The threat type is classified as a government impersonation phishing scam, which is particularly dangerous due to its potential to facilitate identity theft, tax fraud, and unauthorized access to IRS accounts. This domain currently resolves to the IP address 43.166.241.242, which is hosted on infrastructure known for supporting phishing campaigns. As of the latest scan, VirusTotal reports 0 detections out of 95 security engines, indicating that the domain has not yet been widely flagged by antivirus or threat intelligence platforms. The domain is registered through an offshore registrar, which often complicates takedown efforts due to less stringent abuse policies. No creation date is publicly available, but the domain's structure—using 'phila' to mimic the Philadelphia IRS office and 'revenuefr' to suggest a revenue or financial portal—strongly suggests malicious intent. The domain is not currently listed on major blocklists, and its trust scores remain neutral due to the lack of prior detections. However, its recent takedown status indicates that hosting providers or registrars have already intervened, likely due to abuse reports. Users who may have interacted with phila.revenuefr.cc should immediately take steps to mitigate potential damage. First, do not enter any additional information or attempt to log in to the site. If credentials were submitted, change passwords for IRS.gov and any other accounts using the same login details. Enable multi-factor authentication (MFA) on all financial and government accounts to prevent unauthorized access. Monitor bank statements, credit reports, and IRS communications for signs of fraudulent activity, such as unexpected tax filings or refunds. Report the incident to the IRS Identity Theft Protection Unit and file a complaint with the Federal Trade Commission (FTC) at IdentityTheft.gov. For organizations or individuals who encountered this domain, block the IP address 43.166.241.242 and the domain itself at the firewall or DNS level to prevent further exposure. Always verify the legitimacy of tax-related websites by ensuring they use the official IRS.gov domain and look for HTTPS encryption and valid security certificates.
Alur Tanggapan Ancaman Pipeline
Status Daftar Blokir Publik
Tangkapan tersimpan
Intelijen Domain
Rincian teknisDNS, SAN SSL, cap waktu
Analisis VirusTotal
Bukti & Laporan Eksternal
Apakah Anda Terpengaruh oleh Situs Ini?
Jika Anda memasukkan kredensial akun, informasi pribadi atau pembayaran, atau mengunduh file dari domain ini, segera ambil tindakan. Di bawah ini adalah sumber daya untuk membantu Anda melaporkan insiden tersebut dan melindungi diri Anda sendiri.
Laporkan kepada Pihak Berwenang di Daerah Anda
Pilih negara Anda untuk mendapatkan kontak resmi kejahatan dunia maya, atau membuat draf pengaduan →.
Periksa Domain Apa Pun
Analisis ancaman menggunakan daftar blokir yang disimpan, WHOIS, DNS, dan bukti pemindaian publik
Pindai SekarangLaporkan Phishing
Laporkan domain yang mencurigakan ke basis data ancaman kami — lindungi komunitas
LaporanPemberitahuan Ancaman Real-Time
Laporan phishing terbaru dan perubahan ketersediaan yang diamati
PantauTetap Terinformasi, Tetap Aman
Pantau ancaman secara langsung atau ajukan keberatan terhadap daftar ini jika Anda yakin ini merupakan false positive