phila[.]revenhtf[.]cc
“Florida Dept. of Revenue Florida Dept. of Revenue”
phila.revenhtf.cc — İçerik kullanılamıyor (HTTP 502). Marka kimliğine bürünme: Govphil. Kanıt özeti: VirusTotal 14/91 (ADMINUSLabs, BitDefender, CRDF, CyRadar, ESET); URLScan malicious verdict; PhishDestroy score 92/100. Kayıt kuruluşu: Dominet (HK).
Özgün adli kaydı korumak için aşağıdaki ayrıntılı PhishDestroy AI analizi İngilizce bırakılmıştır.
Analysis of the domain phila.revenhtf.cc, observed on July 29 2026, indicates that it was registered on September 16 2025 through Dominet (HK) Limited, a registrar known for hosting a variety of short‑lived domains. The domain resolves to the IPv4 address 170.106.160.91, which is currently associated with a hosting provider that has been referenced by multiple security feeds, but no further attribution such as ASN or country is provided in the available data. Reputation services have placed the domain on a single security blocklist, and the blocklist operator PhishDestroy actively blocks traffic to it, suggesting that at least one defensive network has identified malicious use.
VirusTotal observations show that 14 out of 91 scanning engines flag the domain as malicious, reinforcing the blocklist indication and providing independent corroboration of suspicious activity. The limited detection count and the presence on only one public blocklist imply that the campaign may be in an early or low‑volume phase, yet the consistent identification by multiple vendors demonstrates a non‑trivial risk. No public information about SSL certificates, HTTP response codes, page titles, or targeted brands has been published, leaving the exact content and lure technique of the site uncertain.
Defenders should therefore treat the domain as high‑confidence malicious, update intrusion‑detection signatures, enforce outbound filtering rules to block connections to 170.106.160.91, and add the domain to internal blocklists. Continuous monitoring of the registrar Dominet (HK) Limited and of any new sightings of the IP address is advised, as the infrastructure could be reused for additional campaigns. Until further forensic analysis of the hosted content is performed, the domain should be considered unsafe for end‑user interaction.
Ağ Güvenliği İstihbaratı
Tehdit Müdahale Pipeline
Genel Engelleme Listesi Durumu
Kaydedilen görüntü
Etki Alanı Analizi
Teknik ayrıntılarDNS, SSL SAN’ları, zaman damgaları
VirusTotal Analizi
Kanıtlar ve Dış Raporlar
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin