Certificate for web theft phucnha.com

phucnha[.]com has certificate from letsencrypt
they attend to charge to Citi credit card accounts

443/tcp open ssl/http nginx
| ssl-cert: Subject: commonName=phucnha.com
| Subject Alternative Name: DNS:phucnha.com
| Issuer: commonName=R13/organizationName=Let's Encrypt/countryName=US
| Public Key type: rsa
| Public Key bits: 2048
| Signature Algorithm: sha256WithRSAEncryption
| Not valid before: 2026-04-22T02:19:44
| Not valid after: 2026-07-21T02:19:43
| MD5: 0bca7f477d092a16dbc77b540ec68220
|_SHA-1: 3fcdf0d098b3b3501c2d2225dd180659e1a50c4c

Please see: The CA's Role in Fighting Phishing and Malware - Let's Encrypt

This article is over TEN (10) years old. Perhaps an update is in order. Thank you.

It has been updated in 2019 and is current.

@DG12 You could report that site as described here: Phishing site where people are scammed - #2 by JamesLE

I agree. Revoking certificates is significantly slower than reporting the domain to Google Safe Browsing. Certificate revocation is also very flaky, since most clients don't check individual certs for revocation.