teleukpfh.com
“Messenger”
Analysis indicates that the domain www.teleukpfh.com is actively engaged in credential phishing targeting users of a messaging platform, as evidenced by its pag
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
证据摘要
Analysis indicates that the domain www.teleukpfh.com is actively engaged in credential phishing targeting users of a messaging platform, as evidenced by its page title 'Messenger' and classification under 'Credential Phishing' in threat intelligence sources. Registered on May 18, 2026, through NICENIC INTERNATIONAL GROUP CO., LIMITED, the domain resolves to the IP address 27.124.47.186, hosted on AS152194 (CTG Server Limited) in Hong Kong. Infrastructure analysis reveals the use of nameservers ns3.my-nddns.com and ns4.my-nddns.com, while its SSL certificate is issued for 'Telegram' and a wildcard subdomain *.local, which may suggest an attempt to mimic legitimate communication services. As of July 12, 2026, the domain returns an HTTP 200 status, confirming its operational status. Detection metrics from security vendors indicate partial confirmation of malicious activity, with 7 out of 91 engines flagging the domain. The domain appears on at least one security blocklist and is actively blocked by PhishDestroy. Gridinsoft assigns a trust score of 0/100, further supporting its classification as high-risk. While the exact content and functionality of the phishing page remain unanalyzed, the combination of infrastructure, registration details, and detection data confirms its role in credential harvesting. Defenders are advised to treat this domain as malicious, implement network-level blocking, and monitor for related indicators of compromise. Additional investigation into the hosting provider and registrar may reveal further connections to broader phishing campaigns.
网络安全情报 Registrar context
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | www.teleukpfh.com |
malicious | Sinkholed |
Forensic History & Detection Timeline
-
VirusTotal Detections Update Jun 27, 2026 · 23:04 UTCVirusTotal scanner detections updated from None to 7. Added scanner alerts: ADMINUSLabs, BitDefender, CyRadar, ESET, Fortinet, G-Data, alphaMountain.ai.
威胁响应 Pipeline
公共封禁名单状态
Evasion analysis
Cloaking & traffic-distribution check
Stored crawler-versus-browser observations for this host, plus a live fingerprint check for Keitaro-style traffic distribution systems.
- Stored cloaking flag
- Not observed
- 伪装评分
- 0/6
- Last cloaking scan
Scanner note: timeout: raw=timeout; http=0; via=http_proxy; error=HTTPConnectionPool(host='45.41.179.42', port=6577): Read timed out. (read timeout=7)
Latest Classified Outcome 2026-09-20 02:35:33 UTC
VirusTotal 分析
存档证据
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。