ezpass[.]paylky[.]cc
ezpass.paylky.cc — Não verificado. Tipo de golpe: Credential Phishing. Resumo das evidências: VirusTotal 10/91 (BitDefender, CyRadar, ESET, Forcepoint ThreatSeeker, Fortinet); PhishDestroy score 88/100. Registrador: Gname.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
This domain, ezpass.paylky.cc, is identified as a credential theft operation impersonating electronic toll collection services. Analysis indicates the infrastructure was designed to harvest login credentials and payment details from unsuspecting users attempting to resolve toll charges. The domain exhibits no direct ties to known cryptocurrency drainer kits but aligns with broader credential harvesting campaigns targeting transportation and financial sectors. Infrastructure analysis reveals the domain was registered on June 12, 2026, through Gname.com Pte. Ltd. and resolves to the IP address 172.67.183.196. VirusTotal detection metrics show 11 out of 95 security vendors flagging the domain as malicious, while it appears on a single security blocklist. The SSL certificate is issued by Google Trust Services, a common tactic to lend superficial legitimacy. No Google Safe Browsing (GSB) entries were recorded at the time of assessment, though this may reflect detection latency rather than benign status. The domain is currently offline, having been taken down following automated and manual intervention. Despite its inactive status, residual risk persists due to potential cached DNS entries or delayed user interaction with phishing emails or SMS messages directing traffic to the domain. Organizations are advised to monitor for failed authentication attempts or anomalous access patterns linked to toll service credentials. Network-level blocking of the IP 172.67.183.196 and the domain ezpass.paylky.cc is recommended as a precautionary measure. Users should verify all toll-related communications through official channels and avoid entering credentials on untrusted portals.
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Captura armazenada
Inteligência de Domínios
Detalhes técnicosDNS, SANs do SSL, carimbos de data e hora
Análise do VirusTotal
Evidências e relatórios externos
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo