mass[.]hvpaybrf[.]cc
“MassTaxConnect”
mass.hvpaybrf.cc — Conteúdo indisponível. Representação da marca: Govmass. Resumo das evidências: VirusTotal 6/91 (alphaMountain.ai, Forcepoint ThreatSeeker, Fortinet, Gridinsoft, SOCRadar); URLScan malicious verdict; Spamhaus DBL_PHISH; PhishDestroy score 68/100. Registrador: Dominet (HK).
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
mass.hvpaybrf.cc is currently classified as an active generic phishing domain, presenting an elevated risk profile for network defenders. The domain resolves to IP address 172.67.167.97 and was registered through Dominet (HK) Limited on September 19, 2025. Security intelligence indicates the domain appears on one blocklist and has been explicitly blocked by PhishDestroy, confirming its identification as a threat. VirusTotal analysis shows that 6 out of 91 security vendors have flagged the domain, corroborating its malicious status.
The domain's ongoing activity as of July 29, 2026, suggests it remains operational and should be considered untrusted by default. While exact page content and scam type are not yet analysed, the consistent detections across multiple platforms and inclusion in a blocklist provide sufficient evidence to treat mass.hvpaybrf.cc as part of phishing infrastructure. No specific brand or kit is associated with the domain based on current intelligence, and there is no evidence of Safe Browsing or OTX checks in the available data.
Defenders should immediately block traffic to mass.hvpaybrf.cc at both network and endpoint levels. Monitoring for related domains registered via Dominet (HK) Limited or resolving to 172.67.167.97 is advised, as these may indicate broader phishing activity. Continued surveillance for further detection and blocklist appearances is recommended to track any escalation or changes in threat posture. No legitimate activity has been observed, and the domain's status as active, combined with multiple detection sources, warrants ongoing vigilance and strict exclusion from trusted networks.
Inteligência de segurança de rede
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Captura armazenada
Inteligência de Domínios
Detalhes técnicosDNS, SANs do SSL, carimbos de data e hora
Análise do VirusTotal
Evidências e relatórios externos
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo