t-mobile[.]vidnufa[.]cc
“Welcome to nginx!”
t-mobile.vidnufa.cc — المحتوى غير متوفر (HTTP 502). ملخص الأدلة: VirusTotal 14/93 (ADMINUSLabs, BitDefender, Cluster25, CRDF, Forcepoint ThreatSeeker); PhishDestroy score 92/100. مسجّل النطاق: Gname.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
The domain t-mobile.vidnufa.cc was registered on February 21, 2026 through Gname.com Pte. Ltd. and is presently offline, having been taken down after detection. Infrastructure analysis shows the domain resolves to IP address 172.67.146.123, which belongs to AS13335 Cloudflare, Inc., located in the United States. The authoritative name servers are aspen.ns.cloudflare.com and trevor.ns.cloudflare.com, indicating Cloudflare DNS services. No SSL certificate is presented; HTTP requests return the default page title "Welcome to nginx!", suggesting the web server is serving a generic Nginx landing page rather than a customized phishing page.
The threat is classified as brand impersonation targeting x.com, as indicated by the supplied intelligence. Gridinsoft assigns a trust score of 0 out of 100, reflecting an extremely low reputation. VirusTotal analysis reports that 14 of 93 scanned security vendors flag the domain as malicious, reinforcing the suspicion. The domain appears on a single security blocklist and has been blocked by the PhishDestroy service.
Given the Cloudflare hosting, defenders should consider blocking the associated ASN (AS13335) or the specific IP address to mitigate possible collateral traffic. Adding t-mobile.vidnufa.cc to internal URL filtering, DNS sinkhole, and endpoint allowlists will prevent accidental access. Continuous monitoring of the registrar Gname.com for any re‑registration attempts and periodic re‑scanning of the domain are recommended to detect any resurgence of activity. The lack of an SSL certificate and the generic Nginx title limit immediate forensic insight into content, so threat hunters should treat the domain as a high‑confidence impersonation indicator and prioritize defensive rule deployment.
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
تحليل VirusTotal
الأدلة والتقارير الخارجية
PD-20260203-70C420 Recipient: complaint@gname.com هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب