telegoev.com
“Messenger”
www.telegoev.com is a generic phishing domain with page title Messenger and SSL certificate for Telegram, created May 25, 2026, flagged by 7/95 VirusTotal.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
证据摘要
This domain presents a high risk level as a generic phishing threat. Infrastructure analysis reveals that www.telegoev.com is actively impersonating Messenger services through a fabricated login interface to harvest credentials from unsuspecting visitors. The site remains fully operational and continues to serve deceptive content designed to mimic trusted communication platforms.
Technical indicators include creation on May 25, 2026 via registrar NICENIC INTERNATIONAL GROUP CO., LIMITED, resolution to IP 27.124.47.186, and an SSL certificate issued under the Telegram name. VirusTotal detection stands at 7/95 security vendors, confirming malicious classification while the page title explicitly reads Messenger. No additional blocklists or trust scores are recorded beyond these primary indicators.
Mitigation requires immediate avoidance of any credential submission on www.telegoev.com, verification that all Messenger-related URLs match official domains, and reporting of the active phishing page to hosting providers and threat intelligence platforms. Organizations should enforce URL filtering for the identified IP 27.124.47.186 and educate users on checking SSL certificate details before interaction.
网络安全情报 Registrar context
威胁响应 Pipeline
公共封禁名单状态
Evasion analysis
Cloaking & traffic-distribution check
Stored crawler-versus-browser observations for this host, plus a live fingerprint check for Keitaro-style traffic distribution systems.
- Stored cloaking flag
- Not observed
- 伪装评分
- 0/6
- Last cloaking scan
Scanner note: timeout: raw=timeout; http=0; via=http_proxy; error=HTTPConnectionPool(host='31.58.148.181', port=7923): Read timed out. (read timeout=7)
Latest Classified Outcome 2026-09-20 02:35:16 UTC
VirusTotal 分析
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。