att[.]ejpqu[.]cc
“Welcome to nginx!”
ملخص الأدلة
The domain att.ejpqu.cc is identified as a brand impersonation threat specifically targeting x.com, the social media platform. Analysis indicates the domain was designed to mimic legitimate login pages, likely to harvest user credentials or facilitate unauthorized account access. As of the latest assessment, the domain has been taken offline, though its infrastructure remains documented for investigative purposes. Infrastructure analysis reveals the domain was registered on February 21, 2026, through Gname.com Pte. Ltd., a registrar frequently associated with high-risk domains. It resolved to the IP address 172.67.188.24, hosted on Cloudflare’s network (AS13335). The domain is flagged by 17 of 95 security vendors on VirusTotal, and it appears on at least one security blocklist. The page title, 'Welcome to nginx!', suggests a misconfigured or placeholder server, which may indicate either an incomplete deployment or an attempt to evade detection. No SSL certificate was observed, further reducing its apparent legitimacy. At present, att.ejpqu.cc is offline, though its historical activity warrants continued monitoring. Organizations and users are advised to block the domain at the network level and review logs for prior connections. Security teams should treat any residual references to this domain as malicious and investigate associated IP addresses for lateral movement or persistence. Proactive measures, such as domain-based email filtering and endpoint detection rules, are recommended to mitigate similar threats targeting brand impersonation.
لقطة الأدلة المرسلة
- أُرسل
- سجلات الدفتر
- 1
- معرّف القضية
PD-20260120-02F934- عنوان الصفحة الملتقطة
- Welcome to nginx!
- ملف PDF
- دليل PDF
النص الكامل للدليل
Policy Violations: Illegal Activities section forbids phishing, fraud, fake sites, malware distribution; registrar investigates and may suspend or delete domain
Applicable Laws: Computer Misuse Act 1993 §§3+, Penal Code §§415–420 (cheating), Online Criminal Harms Act (OCHA)
Data Coverage
استخبارات أمن الشبكات
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | att.ejpqu.cc |
malicious | Sinkholed |
مسار الاستجابة للتهديدات Pipeline
تغطية قوائم الحظر
١٠ مصادر خارجية مراقبة · لقطة محفوظة 11/08/2026
المخطط الزمني للاكتشاف
-
Cloudflare Radar
تم حفظ فحص Cloudflare Radar · فتح الفحص
تحليل VirusTotal
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب