mijn[.]belastingdienst[.]nl[.]kwrfnsnqeeqxafzdr7hbjly8gd99g3yrjqqmtsaxqqtxzeo6f2a9[.]aizman[.]com[.]br
“Mijn Belastingdienst”
mijn.belastingdienst.nl.kwrfnsnqeeqxafzdr7hbjly8gd99g3yrjqqmtsaxqqtxzeo6f2a9.aizman.com.br — 콘텐츠를 사용할 수 없음 (HTTP 502). 브랜드 사칭: Bybit; 사기 유형: Brand Impersonation. 증거 요약: VirusTotal 3/95 (Emsisoft, Netcraft, SOCRadar); URLQuery 100 det.; URLScan malicious verdict; PhishDestroy score 95/100.
원본 포렌식 기록을 보존하기 위해 아래의 상세 PhishDestroy AI 분석은 영어로 유지됩니다.
The domain mijn.belastingdienst.nl.kwrfnsnqeeqxafzdr7hbjly8gd99g3yrjqqmtsaxqqtxzeo6f2a9.aizman.com.br was flagged as an elevated‑risk brand‑impersonation campaign targeting the cryptocurrency exchange Bybit. The site’s page title, "Mijn Belastingdienst," suggests an attempt to masquerade as a Dutch tax authority, yet the intelligence explicitly classifies the threat as a Bybit impersonation, indicating a mismatch between visible branding and the intended victim set. Technical observations reveal that the domain resolves to IP address 187.110.161.85, which belongs to ASN 53107 (EVEO S.A.) located in Brazil. The hosting provider therefore resides outside the primary target geography, a pattern common in malicious infrastructure. The domain registration date is 2 June 2006, implying that the name may have been repurposed after long‑term dormancy, a tactic used to leverage existing DNS reputation.
No SSL certificate is present, meaning the site operates over plain HTTP, simplifying detection by network‑level filters. The Gridinsoft trust score of 0 out of 100 marks the domain as extremely untrustworthy. It appears on a single security blocklist and has been actively blocked by PhishDestroy, demonstrating that at least one dedicated anti‑phishing service has taken remediation steps. VirusTotal analysis shows three of ninety‑five scanners flagged the domain, providing additional confirmation of malicious intent.
Nameserver information is unavailable (NS_NOT_FOUND), limiting the ability to trace authoritative records. Current status is offline, indicating the site has been taken down or is no longer serving content. Defenders should continue to block the full domain string and any sub‑domains derived from the observed pattern, monitor the associated IP range and ASN for related activity, and update host‑based or DNS‑based filtering solutions with the observed indicators.
위협 대응 Pipeline
공개 차단 목록 상태
VirusTotal 분석
증거 및 외부 보고서
이 사이트로 인해 영향을 받으셨나요?
계정 자격 증명, 개인 정보 또는 결제 정보를 입력했거나 이 도메인에서 파일을 다운로드한 경우 즉시 조치를 취하세요. 다음은 사건을 신고하고 자신을 보호하는 데 도움이 되는 리소스입니다.
지역 당국에 신고하십시오
공식 사이버 범죄 연락처 또는 불만사항 초안 작성 →를 받으려면 국가를 선택하세요.