MALICIOUS — CRITICAL
teoutf[.]sbs
This domain is flagged as an elevated-risk phishing site impersonating Telegram, a messaging platform.
- VirusTotal
- 17/91
- Blocklists
- No stored match
- Ketersediaan
- Konten tidak tersedia · HTTP 502
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
teoutf.sbs — Konten tidak tersedia (HTTP 502). Peniruan identitas merek: Telegram; Jenis penipuan: Brand Impersonation. Ringkasan bukti: VirusTotal 17/91 (alphaMountain.ai, BitDefender, Chong Lua Dao, CRDF, CyRadar); URLQuery 1 alert; URLScan malicious verdict; Spamhaus DBL_SPAM; PhishDestroy score 95/100. Registrar: NiceNIC.
Analisis terperinci PhishDestroy AI di bawah tetap berbahasa Inggris untuk menjaga catatan forensik asli.
Evidence Analysis
This domain is flagged as an elevated-risk phishing site impersonating Telegram, a messaging platform. Analysis indicates the infrastructure was designed to deceive users into believing they were interacting with legitimate Telegram services, likely through fake login portals or fraudulent account verification pages. The use of Telegram branding in the SSL certificate suggests an attempt to lend credibility to the phishing operation by mimicking the platform's security indicators. Infrastructure analysis reveals the domain was registered through NICENIC INTERNATIONAL GROUP CO., LIMITED on June 14, 2026, an unusually future-dated registration that may indicate automated or bulk domain creation. The domain resolves to IP address 216.150.1.1, which has been associated with other malicious activity in prior investigations. Security vendors on VirusTotal flagged the domain with 15/95 detections, while Gridinsoft assigned a trust score of 0/100. The domain appears on one security blocklist and was actively blocked by PhishDestroy. The page title 'Loading...' suggests the site may have employed evasion techniques to delay or obscure its malicious content from automated scanners. Mitigation for this Telegram impersonation threat requires immediate action from network defenders and end-users. Organizations should block the domain at the DNS or proxy level and add the IP address 216.150.1.1 to firewall deny lists. Users who may have interacted with the site should be instructed to reset their Telegram credentials from a secure device and enable multi-factor authentication. Security teams should monitor for unauthorized access attempts or anomalous login activity, particularly from the IP range associated with this phishing infrastructure. Given the future-dated registration, additional domains from the same registrar should be scrutinized for similar patterns.
Cakupan data13 recorded checks
Intelijen Keamanan Jaringan Registrar context
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | teoutf.sbs |
malicious | Sinkholed |
Alur Tanggapan Ancaman Pipeline
Status Daftar Blokir Publik
Tangkapan tersimpan
Intelijen Domain
Rincian teknisDNS, SAN SSL, cap waktu
ZONA SHORTDOT · BUKTI PUBLIK
.sbs
ShortDot zone evidence
ShortDot zone evidence
The linked repository preserves daily zone observations across seven ShortDot-operated TLDs, including registration volume and abuse-related indicators. This registry context is supporting background and is not an independent detection for the domain in this report.
ICANN OVERSIGHT
Akreditasi dan konteks RAA
Akreditasi dan konteks RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Latest Classified Outcome 2026-08-05 19:12:49 UTC
Analisis VirusTotal
Bukti & Laporan EksternalIndependent lookups and source reports
PD-20260617-CF7EBC Recipient: abuse@vercel.com Victim safety and official reportingImmediate actions and verified reporting channels
Jika Anda memasukkan kredensial akun, informasi pribadi atau pembayaran, atau mengunduh file dari domain ini, segera ambil tindakan. Di bawah ini adalah sumber daya untuk membantu Anda melaporkan insiden tersebut dan melindungi diri Anda sendiri.
Laporkan kepada Pihak Berwenang di Daerah Anda
Pilih negara Anda untuk mendapatkan kontak resmi kejahatan dunia maya, atau membuat draf pengaduan →.