phila[.]revenue-ru[.]cc
“phila.revenue-ru.cc”
phila.revenue-ru.cc — コンテンツが利用できません. 証拠の概要: VirusTotal 7/91 (alphaMountain.ai, CRDF, Forcepoint ThreatSeeker, Fortinet, Gridinsoft); PhishDestroy score 71/100. レジストラ: Dominet (HK).
元のフォレンジック記録を保持するため、下の PhishDestroy AI 詳細分析は英語のままです。
On July 29, 2026 the domain phila.revenue-ru.cc is listed as active with an elevated risk rating. The domain was registered on September 18, 2025 through Dominet (HK) Limited, a registrar known for allowing rapid registration of short‑lived sites. DNS resolution points to the IPv4 address 170.106.51.191, which is the sole hosting endpoint observed for this indicator. Threat intelligence platforms have flagged the domain as malicious: VirusTotal reports 7 of 91 scanned vendors labeling it as malicious, and the domain is currently listed on one public security blocklist.
Additionally, the PhishDestroy service has added the domain to its blocklist, confirming that it is being used for phishing‑related campaigns. No public information is available regarding the site’s SSL certificate, HTTP response codes, or page title, indicating that those artefacts have not yet been captured or released. The limited visibility suggests that the infrastructure may be short‑lived or that the operators are employing fast‑flux techniques to evade detection. Defenders should block the domain at network perimeter devices, update DNS sinkhole feeds, and add the resolving IP address 170.106.51.191 to host‑based deny lists.
Monitoring for credential‑harvesting attempts targeting the same brand or similar domain patterns is advised, as the naming convention implies an attempt to impersonate revenue‑related services. Continuous re‑scanning with multi‑engine platforms such as VirusTotal is recommended to capture any changes in payload or hosting. Organizations should also consider user‑education campaigns that highlight the risk of unsolicited communications referencing revenue or tax authorities, given the domain’s naming strategy. Until further forensic detail is released, the domain remains a credible threat vector and should be treated accordingly.
ネットワークセキュリティインテリジェンス
脅威対応 Pipeline
公開ブロックリスト登録状況
保存済みキャプチャ
ドメイン・インテリジェンス
技術的な詳細DNS、SSL SAN、タイムスタンプ
VirusTotalによる分析
証拠および外部報告書
このサイトによって何か影響を受けましたか?
アカウント資格情報、個人情報、支払い情報を入力した場合、またはこのドメインからファイルをダウンロードした場合は、すぐに対処してください。インシデントを報告し、自分自身を守るのに役立つリソースを以下に示します。
お住まいの地域の当局へ報告してください
サイバー犯罪の公式連絡先 または 苦情草稿を作成する → を取得するには、国を選択してください。
任意のドメインを確認する
保存されたブロックリスト、WHOIS、DNS、および公開スキャン証拠を使用した脅威分析
今すぐスキャンフィッシングを報告する
不審なドメインを当社の脅威データベースに報告してください — コミュニティを守りましょう
レポートリアルタイム脅威情報フィード
最近のフィッシングレポートと観察された可用性の変化
監視最新情報を入手し、安全を確保しましょう
リアルタイムの脅威を監視するか、誤検知だと思われる場合はこのリストに異議を申し立ててください