t-mobile[.]com-viodf[.]cc
“Welcome to nginx!”
ملخص الأدلة
Analysis indicates that the domain t-mobile.com-viodf.cc was registered on 21 February 2026 through Gname.com Pte. Ltd. and is currently taken offline. The site resolves to the Cloudflare‑owned address 188.114.96.3 (AS13335, United States) and was served via nginx with a default “Welcome to nginx!” title, suggesting no custom landing page was observed before takedown. The infrastructure uses Cloudflare nameservers dilbert.ns.cloudflare.com and riya.ns.cloudflare.com and supports HTTP/3, confirming the presence of a modern CDN front‑end. The SSL certificate presented is issued by Google Trust Services under the WE1 hierarchy, indicating a valid TLS chain despite the malicious intent.
The domain is classified as a brand‑impersonation campaign targeting the x.com brand. Gridinsoft assigned a trust score of 0/100, and the domain appears on one external blocklist. PhishDestroy has already blocked the domain, and VirusTotal reports that 20 of 93 scanned security vendors flagged the host as malicious, reinforcing the suspicion of abuse. At present no artifacts such as phishing email samples, credential‑harvesting URLs, or malicious payload hashes have been released, so the operational scope cannot be fully quantified.
Defenders should immediately add t-mobile.com-viodf.cc to network and email filtering rules, enforce DNS‑based blocking, and monitor traffic to the associated IP 188.114.96.3 for any residual activity. Because the domain leveraged a legitimate SSL certificate and Cloudflare’s CDN, it may have been used to host short‑lived credential‑harvesting pages that are no longer reachable; continuous observation of the IP range and related sub‑domains is advised. Organizations should also review recent login attempts to x.com from the IP range and consider enforcing multi‑factor authentication for accounts that may have been targeted.
لقطة الأدلة المرسلة
- أُرسل
- سجلات الدفتر
- 1
- معرّف القضية
PD-20260204-3B1A16- ملف PDF
- دليل PDF
النص الكامل للدليل
Policy Violations: Illegal Activities section forbids phishing, fraud, fake sites, malware distribution; registrar investigates and may suspend or delete domain
Applicable Laws: Computer Misuse Act 1993 §§3+, Penal Code §§415–420 (cheating), Online Criminal Harms Act (OCHA)
Data Coverage
استخبارات أمن الشبكات
مسار الاستجابة للتهديدات Pipeline
تغطية قوائم الحظر
١٠ مصادر خارجية مراقبة · لقطة محفوظة 13/08/2026
المخطط الزمني للاكتشاف
تحليل VirusTotal
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب