phila[.]revenuelxt[.]cc
“502 Bad Gateway”
phila.revenuelxt.cc — Неперевірений. Тип шахрайства: Credential Phishing. Зведення доказів: VirusTotal 5/91 (Forcepoint ThreatSeeker, Fortinet, Gridinsoft, SOCRadar, Webroot); PhishDestroy score 65/100. Реєстратор: Dominet (HK).
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
This domain, phila.revenuelxt.cc, is identified as a fake login portal designed to harvest user credentials through cloned authentication interfaces. Analysis indicates the infrastructure was engineered to mimic legitimate login pages, likely targeting corporate or financial service users. No specific brand impersonation or cryptocurrency drainer kit signatures have been confirmed, but the presence of credential capture scripts aligns with typical phishing toolkits observed in similar campaigns. Infrastructure analysis reveals the following technical indicators: the domain is flagged by 5 out of 95 security vendors on VirusTotal, registered through Dominet (HK) Limited, and resolves to the IP address 43.166.241.242. The domain was created on June 12, 2026, and currently appears on one security blocklist, with no detections from Google Safe Browsing at the time of assessment. The SSL certificate is issued by DigiCert Inc, which may lend a superficial layer of legitimacy to unsuspecting users. The domain is currently offline, likely taken down following detection by security mechanisms. However, residual risk remains due to the potential reuse of the underlying infrastructure or registration patterns for future phishing campaigns. Organizations are advised to monitor for related indicators, including the IP address and registrar, and implement domain-based blocking at the network level. Users who may have interacted with the domain should reset credentials and enable multi-factor authentication on affected accounts to mitigate potential compromise.
Розвіддані з мережевої безпеки
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Збережений знімок
Аналітика доменів
Технічні деталіDNS, SAN-адреси SSL, мітки часу
Аналіз VirusTotal
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога