taldvrof[.]sbs
“Messenger”
Сводка доказательств
Analysis of the domain taldvrof.sbs indicates it is an active phishing infrastructure targeting users through a Messenger-themed lure. The domain was registered via NICENIC INTERNATIONAL GROUP CO., LIMITED and resolves to the IP address 27.124.47.186, hosted by Rackip Consultancy Pte. LTD in Hong Kong. The page title explicitly displays 'Messenger,' suggesting an attempt to impersonate the platform for credential harvesting or malware distribution. The SSL certificate, issued for 'Telegram / *.local,' does not align with the expected domain or brand, further signaling misrepresentation. As of July 19, 2026, the domain remains operational, returning an HTTP 200 status, and is flagged by 15 of 91 security vendors on VirusTotal. It is also blocked by PhishDestroy and appears on at least one security blocklist. Nameservers ns3.my-nds.com and ns4.my-nds.com are associated with the domain, though their historical use in similar campaigns is not confirmed in the available data. Defenders should treat this domain as high-risk and prioritize blocking it at the DNS and network layers. Additional monitoring of related infrastructure, particularly IPs and nameservers linked to this registrar or hosting provider, is recommended to identify potential lateral movement or new domains in the same campaign. The exact phishing kit or payload remains unanalyzed, and no specific victim data or targeting patterns have been observed in the current evidence.
Data Coverage
Данные сетевой безопасности
Процесс реагирования на угрозы
Проверка по блок-листам
10 внешних источников под наблюдением · снимок от 13.08.2026
10 внешних источников под наблюдением Совпадений нет
Хронология обнаружения
-
VirusTotal
14 → 15
-
Статус домена
Доступен → Недоступен
Аналитика доменов
Технические деталиDNS, имена TLS и временные метки
ЗОНА SHORTDOT · ПУБЛИЧНЫЕ ДОКАЗАТЕЛЬСТВА
.sbs
ShortDot zone evidence
ShortDot zone evidence
The linked repository preserves daily zone observations across seven ShortDot-operated TLDs, including registration volume and abuse-related indicators. This registry context is supporting background and is not an independent detection for the domain in this report.
ICANN OVERSIGHT
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Анализ VirusTotal
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание