taxopngj[.]sbs
“Messenger”
taxopngj.sbs — Kesalahan server (HTTP 502). Ringkasan bukti: VirusTotal 20/91 (alphaMountain.ai, BitDefender, Chong Lua Dao, Cluster25, CRDF); URLQuery 2 det.; Spamhaus DBL_PHISH; PhishDestroy score 98/100. Registrar: NiceNIC.
Analisis terperinci PhishDestroy AI di bawah tetap berbahasa Inggris untuk menjaga catatan forensik asli.
This domain, taxopngj.sbs, is identified as a high-risk phishing infrastructure designed to impersonate the Messenger platform for credential harvesting. Analysis indicates the domain presents a fraudulent login interface, as evidenced by the page title 'Messenger,' which closely mimics legitimate authentication portals. The objective appears to be the unauthorized collection of user credentials, likely for subsequent account takeover or identity fraud operations. The domain's infrastructure and thematic targeting align with known phishing tactics observed in social media credential theft campaigns. Infrastructure analysis reveals taxopngj.sbs was registered on June 15, 2026, through NICENIC INTERNATIONAL GROUP CO., LIMITED, a registrar frequently associated with high-volume domain registrations linked to malicious activity. The domain resolves to the IP address 27.124.47.186 and has been flagged by 20 out of 95 security vendors on VirusTotal, indicating widespread detection as malicious. Additionally, the domain appears on three security blocklists, including entries in PhishDestroy, PhishingArmy, and Hagezi threat feeds. A Gridinsoft trust score of 0/100 further corroborates its classification as a high-risk entity. AlienVault OTX records the domain in one threat intelligence pulse, suggesting its inclusion in broader malicious campaign tracking. Users who may have interacted with taxopngj.sbs are advised to take immediate remedial action. Any credentials entered on the site should be considered compromised and must be changed immediately across all platforms where identical or similar passwords were used. Affected individuals should enable multi-factor authentication on critical accounts to mitigate the risk of unauthorized access. System scans using updated security tools are recommended to detect potential secondary infections or malware deployed through the phishing infrastructure. Network administrators should block the domain and its associated IP address (27.124.47.186) at the perimeter to prevent further exposure within organizational environments.
Intelijen Keamanan Jaringan Registrar context
Alur Tanggapan Ancaman Pipeline
Status Daftar Blokir Publik
Tangkapan tersimpan
Intelijen Domain
Rincian teknisDNS, SAN SSL, cap waktu
ZONA SHORTDOT · BUKTI PUBLIK
.sbs
ShortDot zone evidence
ShortDot zone evidence
The linked repository preserves daily zone observations across seven ShortDot-operated TLDs, including registration volume and abuse-related indicators. This registry context is supporting background and is not an independent detection for the domain in this report.
ICANN OVERSIGHT
Akreditasi dan konteks RAA
Akreditasi dan konteks RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Latest Classified Outcome 2026-08-18 03:24:11 UTC
Analisis VirusTotal
Bukti & Laporan Eksternal
PD-20260628-F3BC02 Recipient: abuse@rackip.com Apakah Anda Terpengaruh oleh Situs Ini?
Jika Anda memasukkan kredensial akun, informasi pribadi atau pembayaran, atau mengunduh file dari domain ini, segera ambil tindakan. Di bawah ini adalah sumber daya untuk membantu Anda melaporkan insiden tersebut dan melindungi diri Anda sendiri.
Laporkan kepada Pihak Berwenang di Daerah Anda
Pilih negara Anda untuk mendapatkan kontak resmi kejahatan dunia maya, atau membuat draf pengaduan →.
Periksa Domain Apa Pun
Analisis ancaman menggunakan daftar blokir yang disimpan, WHOIS, DNS, dan bukti pemindaian publik
Pindai SekarangLaporkan Phishing
Laporkan domain yang mencurigakan ke basis data ancaman kami — lindungi komunitas
LaporanPemberitahuan Ancaman Real-Time
Laporan phishing terbaru dan perubahan ketersediaan yang diamati
PantauTetap Terinformasi, Tetap Aman
Pantau ancaman secara langsung atau ajukan keberatan terhadap daftar ini jika Anda yakin ini merupakan false positive