phila[.]revenue-ge[.]cc
“Florida Dept. of Revenue Florida Dept. of Revenue”
phila.revenue-ge.cc — Контент недоступен (HTTP 502). Олицетворение бренда: Govphil. Сводка доказательств: VirusTotal 12/91 (ADMINUSLabs, BitDefender, CyRadar, Forcepoint ThreatSeeker, Fortinet); URLScan malicious verdict; PhishDestroy score 86/100. Регистратор: Dominet (HK).
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
The domain phila.revenue-ge.cc was registered on June 12, 2026 through Dominet (HK) Limited, a registrar known for low‑cost bulk registrations. It resolves to the IPv4 address 43.130.77.166, which is currently listed on a single public security blocklist. The domain has been added to the PhishDestroy blacklist, indicating that at least one anti‑phishing service has observed malicious activity originating from it. VirusTotal reports that 12 of 91 scanners label the domain as malicious, a proportion that suggests active exploitation but does not reach the threshold for automatic quarantine by every vendor.
No additional public intelligence such as Safe Browsing, OTX, or SSL certificate details are available in the supplied data, and the page title or any brand targeting information has not been disclosed. Consequently, the precise phishing campaign vector (e.g., credential harvesting, payment redirection) remains unknown. Analysis of the available infrastructure points to a freshly created domain that leverages a shared hosting environment common to many low‑cost fraudulent sites. The combination of a recent registration date, a Hong Kong‑based registrar, and a modest detection footprint aligns with typical patterns observed in generic phishing infrastructure.
Defenders should treat the domain as hostile until further evidence proves otherwise. Recommended actions include adding 43.130.77.166 and the FQDN phila.revenue‑ge.cc to network‑level deny lists, monitoring DNS query logs for repeated lookups, and reviewing any inbound email or web traffic that references the domain for signs of credential‑stealing attempts. Continuous re‑scanning with VirusTotal or similar multi‑engine services is advised to capture any escalation in detection rates. Organizations that rely on the targeted brand’s legitimate services should educate users about unsolicited communications that reference the domain, emphasizing that the domain is not affiliated with any authorized entity.
Данные сетевой безопасности
Процесс реагирования на угрозы
Статус в публичных блок-листах
Сохранённый снимок
Аналитика доменов
Технические сведенияDNS, SAN в протоколе SSL, временные метки
Анализ VirusTotal
Доказательства и внешние отчеты
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание