mn[.]com-cagjk[.]my
“Where's My Refund? | Minnesota Department of Revenue”
mn.com-cagjk.my — 内容不可用. 品牌冒充:Mngov. 证据摘要: VirusTotal 12/91 (alphaMountain.ai, BitDefender, Chong Lua Dao, CyRadar, Forcepoint ThreatSeeker); URLScan malicious verdict; PhishDestroy score 86/100.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
mn.com-cagjk.my was registered on June 12, 2026 and is currently resolving to the IP address 104.21.73.144. The domain appears on a single external blocklist and has been actively listed by the PhishDestroy mitigation service. VirusTotal has recorded twelve positive detections out of ninety‑one submitted scanners, indicating that a notable minority of security products consider the host malicious. The risk rating assigned by the internal taxonomy is elevated and the operational status is marked as active, suggesting ongoing exploitation.
Infrastructure analysis shows the address 104.21.73.144 is hosted on a cloud service provider, a common choice for short‑lived phishing infrastructure because of rapid provisioning and dynamic IP pools. No TLS certificate details, HTTP response codes, or page title information have been published, so the exact content served by the domain remains unverified. Likewise, Safe Browsing, OTX, and other reputation services have not been referenced in the supplied data, leaving those vectors unconfirmed. Given the observed detections, defenders should block the domain at perimeter firewalls, DNS resolvers, and proxy layers.
Security appliances that reference the PhishDestroy blocklist should be updated to ensure the entry is enforced. Incident response teams should monitor for outbound connections to 104.21.73.144 and correlate any suspicious authentication attempts with the domain name. Continuous re‑scanning of the host on VirusTotal and other sandboxes is advised to capture potential payload evolution. Until further forensic details become available, the recommendation is to treat mn.com-cagjk.my as a confirmed phishing host and to apply comprehensive network‑level mitigations.
网络安全情报
威胁响应 Pipeline
公共封禁名单状态
已保存的截图
域名情报
技术细节DNS、SSL SAN、时间戳
VirusTotal 分析
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。