tgelrhgb[.]shop
“Messenger”
tgelrhgb.shop — Belum terverifikasi. Jenis penipuan: Impersonation. Ringkasan bukti: VirusTotal 15/91 (alphaMountain.ai, BitDefender, Chong Lua Dao, CRDF, CyRadar); Spamhaus DBL_SPAM; CF Radar malicious; PhishDestroy score 95/100. Registrar: Nicenic.
Analisis terperinci PhishDestroy AI di bawah tetap berbahasa Inggris untuk menjaga catatan forensik asli.
The domain tgelrhgb.shop is currently active and has been identified as part of a high-risk phishing campaign, specifically impersonating the Messenger platform based on the page title 'Messenger' found during investigation. VirusTotal reports that 15 out of 91 security vendors have flagged this domain as malicious. Additionally, it is blocked by PhishDestroy and appears on at least one public security blocklist, indicating consistent detection across multiple threat intelligence sources.
Infrastructure analysis reveals that tgelrhgb.shop resolves to IP address 27.124.47.186, hosted in Hong Kong through Rackip Consultancy Pte. LTD. The domain's SSL certificate references 'Telegram / *.local', which, combined with the Messenger page title, may suggest broader use of messaging service brands to lure users, though only 'Messenger' is directly referenced in available evidence. The domain uses nameservers ns3.my-ndns.com and ns4.my-ndns.com and is registered via Nicenic International Group Co., Limited. AlienVault OTX includes this domain in two separate threat intelligence pulses, further supporting its malicious classification.
The HTTP status 200 response confirms the domain is currently serving content. However, the exact nature or method of the phishing attempt beyond brand impersonation has not yet been analyzed. Defenders should prioritize blocking this domain, monitor for related infrastructure, and warn users of campaigns leveraging Messenger branding for phishing. Continuous monitoring is advised due to the domain's active status and persistent presence in threat intelligence sources as of July 19, 2026.
Intelijen Keamanan Jaringan Registrar context
Alur Tanggapan Ancaman Pipeline
Status Daftar Blokir Publik
Intelijen Domain
Rincian teknisDNS, SAN SSL, cap waktu
ICANN OVERSIGHT
Akreditasi dan konteks RAA
Akreditasi dan konteks RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Latest Classified Outcome 2026-08-17 02:48:33 UTC
Analisis VirusTotal
Bukti & Laporan Eksternal
Apakah Anda Terpengaruh oleh Situs Ini?
Jika Anda memasukkan kredensial akun, informasi pribadi atau pembayaran, atau mengunduh file dari domain ini, segera ambil tindakan. Di bawah ini adalah sumber daya untuk membantu Anda melaporkan insiden tersebut dan melindungi diri Anda sendiri.
Laporkan kepada Pihak Berwenang di Daerah Anda
Pilih negara Anda untuk mendapatkan kontak resmi kejahatan dunia maya, atau membuat draf pengaduan →.
Periksa Domain Apa Pun
Analisis ancaman menggunakan daftar blokir yang disimpan, WHOIS, DNS, dan bukti pemindaian publik
Pindai SekarangLaporkan Phishing
Laporkan domain yang mencurigakan ke basis data ancaman kami — lindungi komunitas
LaporanPemberitahuan Ancaman Real-Time
Laporan phishing terbaru dan perubahan ketersediaan yang diamati
PantauTetap Terinformasi, Tetap Aman
Pantau ancaman secara langsung atau ajukan keberatan terhadap daftar ini jika Anda yakin ini merupakan false positive