t-mobile[.]thkee[.]cc
“Welcome to nginx!”
ملخص الأدلة
This domain, t-mobile.thkee.cc, is flagged for brand impersonation targeting X.com, a high-profile social media platform. Analysis indicates the infrastructure was configured to mimic legitimate login portals, likely to harvest user credentials or distribute malicious payloads. The absence of a drainer kit signature suggests a focus on direct credential interception rather than cryptocurrency theft, though this cannot be ruled out entirely given the domain's elevated risk profile. Infrastructure analysis reveals concrete technical indicators: the domain resolves to IP 172.67.158.208, hosted on Cloudflare's network (AS13335), and was registered via Gname.com Pte. Ltd. on February 21, 2026. VirusTotal detection shows 14 out of 95 security vendors flagging the domain as malicious, while it appears on a single blocklist. The domain lacks an SSL certificate, a critical omission for any legitimate authentication portal, and displays a generic 'Welcome to nginx!' page title, indicating either incomplete deployment or deliberate obfuscation of its true purpose. As of the latest assessment, t-mobile.thkee.cc has been taken offline, mitigating immediate user exposure. However, the domain's infrastructure remains registered and could be reactivated. The registrar and hosting provider have not publicly disclosed remediation actions, leaving residual risk. Users who may have interacted with the domain are advised to reset credentials for X.com and monitor accounts for unauthorized activity. Organizations should update blocklists to include this domain and its associated IP to prevent potential future exploitation.
لقطة الأدلة المرسلة
- أُرسل
- سجلات الدفتر
- 1
- معرّف القضية
PD-20260203-AFA841- عنوان الصفحة الملتقطة
- Welcome to nginx!
- ملف PDF
- دليل PDF
النص الكامل للدليل
Policy Violations: Illegal Activities section forbids phishing, fraud, fake sites, malware distribution; registrar investigates and may suspend or delete domain
Applicable Laws: Computer Misuse Act 1993 §§3+, Penal Code §§415–420 (cheating), Online Criminal Harms Act (OCHA)
Data Coverage
استخبارات أمن الشبكات
مسار الاستجابة للتهديدات Pipeline
تغطية قوائم الحظر
١٠ مصادر خارجية مراقبة · لقطة محفوظة 13/08/2026
المخطط الزمني للاكتشاف
-
Cloudflare Radar
تم حفظ فحص Cloudflare Radar · فتح الفحص
تحليل VirusTotal
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب