phila[.]revenhtf[.]cc
“Florida Dept. of Revenue Florida Dept. of Revenue”
phila.revenhtf.cc — Контент недоступний (HTTP 502). Уособлення бренду: Govphil. Зведення доказів: VirusTotal 14/91 (ADMINUSLabs, BitDefender, CRDF, CyRadar, ESET); URLScan malicious verdict; PhishDestroy score 92/100. Реєстратор: Dominet (HK).
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
Analysis of the domain phila.revenhtf.cc, observed on July 29 2026, indicates that it was registered on September 16 2025 through Dominet (HK) Limited, a registrar known for hosting a variety of short‑lived domains. The domain resolves to the IPv4 address 170.106.160.91, which is currently associated with a hosting provider that has been referenced by multiple security feeds, but no further attribution such as ASN or country is provided in the available data. Reputation services have placed the domain on a single security blocklist, and the blocklist operator PhishDestroy actively blocks traffic to it, suggesting that at least one defensive network has identified malicious use.
VirusTotal observations show that 14 out of 91 scanning engines flag the domain as malicious, reinforcing the blocklist indication and providing independent corroboration of suspicious activity. The limited detection count and the presence on only one public blocklist imply that the campaign may be in an early or low‑volume phase, yet the consistent identification by multiple vendors demonstrates a non‑trivial risk. No public information about SSL certificates, HTTP response codes, page titles, or targeted brands has been published, leaving the exact content and lure technique of the site uncertain.
Defenders should therefore treat the domain as high‑confidence malicious, update intrusion‑detection signatures, enforce outbound filtering rules to block connections to 170.106.160.91, and add the domain to internal blocklists. Continuous monitoring of the registrar Dominet (HK) Limited and of any new sightings of the IP address is advised, as the infrastructure could be reused for additional campaigns. Until further forensic analysis of the hosted content is performed, the domain should be considered unsafe for end‑user interaction.
Розвіддані з мережевої безпеки
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Збережений знімок
Аналітика доменів
Технічні деталіDNS, SAN-адреси SSL, мітки часу
Аналіз VirusTotal
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога