att[.]mrqvs[.]cc
“Welcome to nginx!”
ملخص الأدلة
The domain att.mrqvs.cc was registered on February 21, 2026 through Gname.com Pte. Ltd. and is currently listed as offline. DNS resolution points to the IP address 188.114.97.3, which belongs to the Cloudflare network (AS13335, United States). The domain is served by two Cloudflare authoritative nameservers, alfred.ns.cloudflare.com and nancy.ns.cloudflare.com, indicating that the attacker leveraged Cloudflare’s DNS and CDN services to obscure the true hosting location. No SSL certificate is presented, and an HTTP request returns the default "Welcome to nginx!" page, confirming the presence of a generic web server with no TLS encryption.
Security intelligence flags the site as a brand impersonation campaign targeting the brand x.com. The Gridinsoft trust score is 0 out of 100, reflecting a maximum risk rating. The domain appears on a single external blocklist, specifically PhishDestroy, which has actively blocked the host. VirusTotal analysis shows that 14 of 95 scanning engines identified the domain as malicious, providing independent vendor corroboration of its illicit nature.
While the available data confirms the infrastructure, the specific payload, phishing kit, or compromised credentials have not been observed, leaving the exact attack vector uncertain. Defenders should immediately add att.mrqvs.cc to network deny lists and block the associated IP 188.114.97.3 at perimeter firewalls. Continuous monitoring of Cloudflare‑associated IP ranges for similar patterns is advised, as the attacker may repurpose the same CDN edge for future campaigns. Future investigations should request full page content, capture any redirected URLs, and verify whether the domain was ever configured with TLS to assess potential credential harvesting tactics.
لقطة الأدلة المرسلة
- أُرسل
- سجلات الدفتر
- 1
- معرّف القضية
PD-20260120-8B6E79- عنوان الصفحة الملتقطة
- Welcome to nginx!
- ملف PDF
- دليل PDF
النص الكامل للدليل
Policy Violations: Illegal Activities section forbids phishing, fraud, fake sites, malware distribution; registrar investigates and may suspend or delete domain
Applicable Laws: Computer Misuse Act 1993 §§3+, Penal Code §§415–420 (cheating), Online Criminal Harms Act (OCHA)
Data Coverage
استخبارات أمن الشبكات
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | att.mrqvs.cc |
malicious | Sinkholed |
مسار الاستجابة للتهديدات Pipeline
تغطية قوائم الحظر
١٠ مصادر خارجية مراقبة · لقطة محفوظة 11/08/2026
المخطط الزمني للاكتشاف
-
Cloudflare Radar
تم حفظ فحص Cloudflare Radar · فتح الفحص
تحليل VirusTotal
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب