t-mobile[.]buis[.]cc
“Welcome to nginx!”
Zusammenfassung der Beweislage
The domain t-mobile.buis.cc was first registered on February 21, 2026 through Gname.com Pte. Ltd. and is presently listed as taken offline. Technical analysis shows the domain resolves to the IP address 188.114.96.3, which belongs to AS13335 Cloudflare, Inc. and is geolocated in the United States. The authoritative nameservers are gordon.ns.cloudflare.com and linda.ns.cloudflare.com, both operated by Cloudflare. An HTTP request to the host returns a default Nginx page with the title "Welcome to nginx!" and no SSL certificate is presented, indicating the site was served over plain HTTP.
Malware and phishing detection services on VirusTotal flagged the domain in 11 of 93 scans, providing independent confirmation of malicious intent. Gridinsoft assigned a trust score of 0 out of 100, reinforcing the low credibility assessment. The domain appears on a single security blocklist and has been explicitly blocked by the PhishDestroy feed. Threat intelligence attributes the activity to a brand impersonation campaign targeting x.com, as indicated by the scam type label and the declared impersonated brand.
The elevated risk rating reflects the combination of recent registration, low trust score, multiple vendor detections, and confirmed blocklist presence. Defenders should add 188.114.96.3 to network deny lists, enforce DNS filtering for t-mobile.buis.cc, and monitor Cloudflare name server changes for potential re‑hosting. Continuous re‑scanning of the domain, even after its offline status, is advisable to capture any future re‑activation attempts.
Momentaufnahme der übermittelten Beweise
- Gesendet
- Protokolleinträge
- 1
- Fall-ID
PD-20260203-927CB7- Titel der erfassten Seite
- Welcome to nginx!
- PDF-Artefakt
- PDF-Beweis
Vollständiger Beweistext
Policy Violations: Illegal Activities section forbids phishing, fraud, fake sites, malware distribution; registrar investigates and may suspend or delete domain
Applicable Laws: Computer Misuse Act 1993 §§3+, Penal Code §§415–420 (cheating), Online Criminal Harms Act (OCHA)
Data Coverage
Pipeline zur Reaktion auf Sicherheitsbedrohungen
Blocklistenabdeckung
10 überwachte externe Feeds · gespeicherter Stand 13.08.2026
Erkennungszeitleiste
-
Cloudflare Radar
Cloudflare-Radar-Scan gespeichert · Scan öffnen
VirusTotal-Analyse
Wurden Sie von dieser Website betroffen?
Wenn Sie Kontoanmeldeinformationen, persönliche oder Zahlungsinformationen eingegeben oder eine Datei von dieser Domain heruntergeladen haben, ergreifen Sie sofort Maßnahmen. Nachfolgend finden Sie Ressourcen, die Ihnen helfen, den Vorfall zu melden und sich zu schützen.
Melden Sie sich bei Ihren örtlichen Behörden
Wählen Sie Ihr Land aus, um Offizielle Kontakte im Bereich Cyberkriminalität oder einen Beschwerdeentwurf erstellen → zu erhalten.
Jede beliebige Domain prüfen
Bedrohungsanalyse anhand gespeicherter Blocklisten, WHOIS, DNS und öffentlicher Scan-Beweise
Jetzt scannenPhishing melden
Melden Sie verdächtige Domains an unsere Bedrohungsdatenbank – schützen Sie die Community
MeldenEchtzeit-Bedrohungsfeed
Aktuelle Phishing-Meldungen und beobachtete Verfügbarkeitsänderungen
ÜberwachenBleiben Sie auf dem Laufenden, bleiben Sie sicher
Beobachten Sie aktuelle Bedrohungen oder legen Sie Widerspruch gegen diesen Eintrag ein, wenn Sie der Meinung sind, dass es sich um einen Fehlalarm handelt