niftex[.]net
“HNFT”
Resumo das evidências
Analysis of the domain niftex.net, created on 21 February 2026, indicates a brand‑impersonation campaign targeting Revolut. The site is currently offline, and its sole observed HTTP response points to a single IPv4 address, 35.220.242.188, which belongs to Google LLC (ASN 396982) and is geolocated in Hong Kong. The TLS certificate presented for the host carries an R10 rating, confirming that a valid SSL certificate was in place at the time of capture.
The page title returned by the server was "HNFT," which does not contain any reference to Revolut and suggests the presence of unrelated or obfuscated content. VirusTotal scans show that two of ninety‑three security vendors flagged the domain as malicious, providing limited but corroborating detection evidence. The domain appears on one public security blocklist and has been explicitly blocked by the PhishDestroy service, reinforcing the assessment that it was being used for fraudulent activities.
While the offline status prevents real‑time interaction, the infrastructure footprint—including the Google Cloud IP, the recent registration date, and the SSL certificate—remains valuable for threat‑intel correlation. Defenders should continue to monitor the IP address for any future redeployment, ensure that internal web filtering solutions block niftex.net, and propagate the indicator to shared blocklists. Additional observation of DNS changes or re‑activation attempts would help confirm whether the actor is reusing the same hosting environment for subsequent campaigns.
Data Coverage
Pipeline de resposta a ameaças
Cobertura de listas de bloqueio
10 fontes externas monitoradas · instantâneo de 11/08/2026
10 fontes externas monitoradas Sem correspondência
Inteligência forense
Análise do VirusTotal
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo