phila[.]revenue-ge[.]cc
“Florida Dept. of Revenue Florida Dept. of Revenue”
phila.revenue-ge.cc — 内容不可用 (HTTP 502). 品牌冒充:Govphil. 证据摘要: VirusTotal 12/91 (ADMINUSLabs, BitDefender, CyRadar, Forcepoint ThreatSeeker, Fortinet); URLScan malicious verdict; PhishDestroy score 86/100. 注册商: Dominet (HK).
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
The domain phila.revenue-ge.cc was registered on June 12, 2026 through Dominet (HK) Limited, a registrar known for low‑cost bulk registrations. It resolves to the IPv4 address 43.130.77.166, which is currently listed on a single public security blocklist. The domain has been added to the PhishDestroy blacklist, indicating that at least one anti‑phishing service has observed malicious activity originating from it. VirusTotal reports that 12 of 91 scanners label the domain as malicious, a proportion that suggests active exploitation but does not reach the threshold for automatic quarantine by every vendor.
No additional public intelligence such as Safe Browsing, OTX, or SSL certificate details are available in the supplied data, and the page title or any brand targeting information has not been disclosed. Consequently, the precise phishing campaign vector (e.g., credential harvesting, payment redirection) remains unknown. Analysis of the available infrastructure points to a freshly created domain that leverages a shared hosting environment common to many low‑cost fraudulent sites. The combination of a recent registration date, a Hong Kong‑based registrar, and a modest detection footprint aligns with typical patterns observed in generic phishing infrastructure.
Defenders should treat the domain as hostile until further evidence proves otherwise. Recommended actions include adding 43.130.77.166 and the FQDN phila.revenue‑ge.cc to network‑level deny lists, monitoring DNS query logs for repeated lookups, and reviewing any inbound email or web traffic that references the domain for signs of credential‑stealing attempts. Continuous re‑scanning with VirusTotal or similar multi‑engine services is advised to capture any escalation in detection rates. Organizations that rely on the targeted brand’s legitimate services should educate users about unsolicited communications that reference the domain, emphasizing that the domain is not affiliated with any authorized entity.
网络安全情报
威胁响应 Pipeline
公共封禁名单状态
已保存的截图
域名情报
技术细节DNS、SSL SAN、时间戳
VirusTotal 分析
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。