Lompat ke laporan keamanan
Checked 09/08/2026 Ref 93D043D9

MALICIOUS — CRITICAL

teoutf[.]sbs

This domain is flagged as an elevated-risk phishing site impersonating Telegram, a messaging platform.

95/100 evidence score · Critical
VirusTotal
17/91
Blocklists
No stored match
Ketersediaan
Konten tidak tersedia · HTTP 502
2026-06-24 08:16 UTCKonten tidak tersedia · HTTP 502

Do not enter credentials, seed phrases, payment details, or personal information on this domain.

⚠️
Domain ini telah ditandai sebagai berbahaya
Mesin keamanan melaporkan deteksi: 17. Berhati-hatilah — jangan memasukkan kredensial atau informasi pribadi.
Jump to section
Ringkasan laporan

teoutf.sbs — Konten tidak tersedia (HTTP 502). Peniruan identitas merek: Telegram; Jenis penipuan: Brand Impersonation. Ringkasan bukti: VirusTotal 17/91 (alphaMountain.ai, BitDefender, Chong Lua Dao, CRDF, CyRadar); URLQuery 1 alert; URLScan malicious verdict; Spamhaus DBL_SPAM; PhishDestroy score 95/100. Registrar: NiceNIC.

Analisis terperinci PhishDestroy AI di bawah tetap berbahasa Inggris untuk menjaga catatan forensik asli.

Evidence Analysis

Ref 93D043D9

This domain is flagged as an elevated-risk phishing site impersonating Telegram, a messaging platform. Analysis indicates the infrastructure was designed to deceive users into believing they were interacting with legitimate Telegram services, likely through fake login portals or fraudulent account verification pages. The use of Telegram branding in the SSL certificate suggests an attempt to lend credibility to the phishing operation by mimicking the platform's security indicators. Infrastructure analysis reveals the domain was registered through NICENIC INTERNATIONAL GROUP CO., LIMITED on June 14, 2026, an unusually future-dated registration that may indicate automated or bulk domain creation. The domain resolves to IP address 216.150.1.1, which has been associated with other malicious activity in prior investigations. Security vendors on VirusTotal flagged the domain with 15/95 detections, while Gridinsoft assigned a trust score of 0/100. The domain appears on one security blocklist and was actively blocked by PhishDestroy. The page title 'Loading...' suggests the site may have employed evasion techniques to delay or obscure its malicious content from automated scanners. Mitigation for this Telegram impersonation threat requires immediate action from network defenders and end-users. Organizations should block the domain at the DNS or proxy level and add the IP address 216.150.1.1 to firewall deny lists. Users who may have interacted with the site should be instructed to reset their Telegram credentials from a secure device and enable multi-factor authentication. Security teams should monitor for unauthorized access attempts or anomalous login activity, particularly from the IP range associated with this phishing infrastructure. Given the future-dated registration, additional domains from the same registrar should be scrutinized for similar patterns.

VirusTotal
VirusTotal
17 det.
URLQuery
URLQuery
1 threat alert
URLScan
URLScan
ScamAdviser
Scamadviser
80/100
Sertifikat TLS
Kedaluwarsa atau belum diverifikasi
Usia
2 mo New
Status terpantau
Konten tidak tersedia 502
PhishDestroy
Daftar Hapus
Terdaftar
Reports Sent
1
Cakupan data13 recorded checks
VirusTotal 17 / 91 URLQuery 1 threat-system alert PhishStats tidak diperiksa OTX no community references CF Radar scan completed URLScan capture laporan yang disimpan URLScan verdict malicious Pemblokiran DNS tidak diperiksa TLS Kedaluwarsa atau belum diverifikasi WHOIS 2 mo old Tangkapan layar 3 captures · 3 sources Rantai pengalihan tidak diselidiki Scamadviser 80/100
Intelijen Keamanan Jaringan Registrar context
Threat Detection Systems 1 alert
Detection System Indicator Verdict Alert
DNS4EU teoutf.sbs malicious Sinkholed
Registrar context NiceNIC
Stored registration data identifies NICENIC INTERNATIONAL GROUP CO., LIMITED (IANA 3765) as the registrar. PhishDestroy maintains separate NiceNIC abuse-report research; registrar association is contextual and is not an independent detection for this domain.
NiceNIC Verdict Full Investigation
SSL Certificate Invalid
SSL certificate is invalid or expired. Issuer: Telegram

Alur Tanggapan Ancaman Pipeline

Penemuan
Checks
Reports
Ketersediaan
17/17
Sent Report Recorded
Stored sent-report record for registrar NICENIC INTERNATIONAL GROUP CO., LIMITED, hosting provider, 2 abuse contacts
abuse@vercel.comabuse@nicenic.net
17/06/2026

Status Daftar Blokir Publik

Tangkapan tersimpan

Sertifikat TLS
Kedaluwarsa atau belum diverifikasi · Diterbitkan oleh Telegram · valid for 811 days

Intelijen Domain

Domain
URLScan Verdict Berbahaya score 100 Phishing brand: Telegram report ↗
Server / ASN Vercel · AS16509 AMAZON-02 - Amazon.com, Inc., US
IP Context Vercel shared edge origin IP hidden Reputasi Edge-IP tidak dikaitkan dengan domain ini.
Alamat IP 216.150.1.1 CDN
LokasiUS Walnut, US
JaringanAS16509 · Amazon.com, Inc.
IP asal tersembunyi di balik proksi CDN. Hasil IP terbalik untuk alamat edge berisi penyewa yang tidak terkait; menemukan asal memerlukan DNS pasif atau data transparansi sertifikat.
PendaftaranDibuat 14/06/2026 (55d · New) Expires 14/06/2027
Status HTTP502 Error
Waktu hingga pertama kali tidak tersedia 47h
Yang kami hitung Waktu yang berlalu sejak laporan penyalahgunaan pertama kali disimpan hingga pengamatan pertama bahwa konten tersebut tidak tersedia. Hal ini tidak dapat menentukan penyebabnya.
Isi setiap laporan Catatan laporan keluar yang disimpan dapat merujuk pada bukti yang tersedia pada saat itu, seperti keputusan vendor, data pendaftaran, detail hosting, klasifikasi, atau tangkapan layar. Halaman ini tidak menyimpulkan secara pasti muatan yang dikirimkan, penerimaan, pengakuan, atau tindakan oleh penerima.
Rincian teknisDNS, SAN SSL, cap waktu
Pertama Kali Terdeteksi17/06/2026
DOM Analysisanalyzed 17/06/2026score 88/100
IoC Extractionscanned 29/07/20260 wallet · 0 Telegram IoCs
Submitted URLhttps://teoutf.sbs/
Server namans3.my-ndns.comns4.my-ndns.com
TLS Fingerprint
TLS Observationvalid from 14/06/2026scanned 17/06/2026
Favicon Hash
Case ID
ZONA SHORTDOT · BUKTI PUBLIK .sbs

ShortDot zone evidence

The linked repository preserves daily zone observations across seven ShortDot-operated TLDs, including registration volume and abuse-related indicators. This registry context is supporting background and is not an independent detection for the domain in this report.

ShortDot SA · Luxembourg 7 zona · bukti seluruh zona diperbarui setiap hari Buka repositori bukti ShortDot
ICANN OVERSIGHT

Akreditasi dan konteks RAA

Registrar accreditation and DNS abuse obligations

For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.

Accreditation is a contract, not a safety certification.

RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.

Accountability draft Tidak ada yang dikirim secara otomatis.

Latest Classified Outcome 2026-08-05 19:12:49 UTC

Primary outcome Registration hold observed reason: Registry serverHold 95% confidence
Attribution actor class: Registry mechanism: Registry serverHold source: Rdap Status Collector
Evidence layers Availability: DNS inactive Content: Unreachable DNS: NXDOMAIN Registration: Registry serverHold
Latest HTTP observation Tidak diketahui Origin unreachable Http 5xx 20% 2026-08-09 01:39:03 UTC
RDAP registration Registry serverHold NICENIC INTERNATIONAL GROUP CO., LIMITED · IANA 3765 RDAP HTTP 200 source: Rdap Status Collector clientDeleteProhibitedclientTransferProhibitedserverHoldServertransferprohibited expires 2027-06-14 23:59:59 UTC checked 2026-08-05 19:12:49 UTC
Observed timeline last reachable: 2026-08-05 22:14:37 UTC current episode first observed: 2026-08-06 01:45:45 UTC observed RIP window: 2026-08-05 22:14:37 UTC → 2026-08-06 01:45:45 UTC · 3.52h midpoint estimate ≈ 2026-08-06 00:00:11 UTC · precision high · basis bounded
Availability, content, DNS and registration are independent evidence layers. NXDOMAIN, an unreachable origin or missing content alone does not prove registrar action. A registrar or provider is credited only when a direct technical marker identifies that actor. Report causality is shown separately.
Laporkan Domain Ini Kirimkan bukti & bantu lindungi orang lain

Analisis VirusTotal

17 / Vendor keamanan 91 menandai domain ini
View on VT
Last analyzed Previous stored snapshot: 15 detections
alphaMountain.ai
BitDefender
Chong Lua Dao
CRDF
CyRadar
ESET
Forcepoint ThreatSeeker
Fortinet
G-Data
Gridinsoft
Kaspersky
LevelBlue
Lionic
SOCRadar
Sophos
VIPRE
Webroot
Bukti & Laporan EksternalIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
If credentials were compromised, report immediately. Do not engage with recovery scammers.

Jika Anda memasukkan kredensial akun, informasi pribadi atau pembayaran, atau mengunduh file dari domain ini, segera ambil tindakan. Di bawah ini adalah sumber daya untuk membantu Anda melaporkan insiden tersebut dan melindungi diri Anda sendiri.

Europol
Temukan saluran pelaporan resmi untuk negara UE Anda
National police directory
Waspadalah terhadap penipu yang mengatasnamakan pemulihan! Penjahat dapat menghubungi korban lagi sambil berpura-pura menjadi penyelidik, pengacara, atau agen pemulihan. Jangan membayar biaya di muka atau membagikan kredensial. Pelajari lebih lanjut tentang penipuan dalam proses pemulihan →

Laporkan kepada Pihak Berwenang di Daerah Anda

Pilih negara Anda untuk mendapatkan kontak resmi kejahatan dunia maya, atau membuat draf pengaduan →.

Direktori 97 negara
Draf yang dibantu AI — detail insiden diproses oleh penyedia AI Tinjau dan kirimkan sendiri
Sematkan Laporan IniRead-only HTML widget
HTML · IFRAME

Sematkan Laporan Ini

Bagikan informasi ancaman ini di situs web atau blog Anda

embed.html
<iframe
  src="https://phishdestroy.io/id/embed/domain/teoutf.sbs"
  title="PhishDestroy threat report for teoutf.sbs"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>

Surat Terima Kasih yang Sangat Tulus

Pembuat draf satir

Penerima
Konteks biaya

Draf satir. Angka biaya merupakan perkiraan; tidak diklaim bahwa angka tersebut secara tepat terkait dengan domain ini.