t-mobile[.]tedhioi[.]cc
“Welcome to nginx!”
t-mobile.tedhioi.cc — Inhalt nicht verfügbar (HTTP 502). Zusammenfassung der Beweislage: VirusTotal 14/93 (ADMINUSLabs, Cluster25, CRDF, CyRadar, ESET); URLQuery 2 alerts; Spamhaus DBL_PHISH; PhishDestroy score 95/100. Registrar: Gname.
Die ausführliche Analyse von PhishDestroy AI bleibt auf Englisch, damit der ursprüngliche forensische Bericht unverändert bleibt.
This domain t-mobile.tedhioi.cc was observed resolving to the Cloudflare‑owned address 104.21.91.95 (AS13335, United States). The hosting provider is Cloudflare, as indicated by the nameservers owen.ns.cloudflare.com and rose.ns.cloudflare.com. No TLS certificate is presented; HTTP connections return the default nginx page with the title “Welcome to nginx!”, which suggests the site is either a placeholder or a minimal landing page without legitimate content. The registrar listed for the domain is Gname.com Pte. Ltd., and the registration timestamp is 21 February 2026. The domain is currently marked offline, and the threat has been classified as brand impersonation targeting the brand x.com.
Threat intelligence shows the domain is blocked by PhishDestroy and appears on a single security blocklist. Gridinsoft assigns a trust score of 0 / 100, indicating no perceived legitimacy. On VirusTotal the domain was flagged by 14 of 93 scanning engines, providing independent confirmation of malicious intent. The absence of an SSL certificate further reduces trustworthiness and may facilitate downgrade‑attack vectors.
Analysts should treat t-mobile.tedhioi.cc as a confirmed malicious infrastructure element. Immediate defensive actions include adding the domain and its resolved IP address to network‑level deny lists, updating DNS filtering policies, and ensuring endpoint protection solutions ingest the VirusTotal detection count. Continued monitoring of the associated Cloudflare IP range is advised, as the provider may be reused for other abusive domains. Because the site currently returns only a generic nginx banner, any future content changes cannot be assessed without direct inspection; therefore, periodic re‑resolution and content retrieval are recommended to capture possible escalation.
Erkenntnisse zur Netzwerksicherheit
Pipeline zur Reaktion auf Sicherheitsbedrohungen
Status der öffentlichen Sperrliste
VirusTotal-Analyse
Nachweise und externe Berichte
PD-20260203-29EA05 Recipient: complaint@gname.com Wurden Sie von dieser Website betroffen?
Wenn Sie Kontoanmeldeinformationen, persönliche oder Zahlungsinformationen eingegeben oder eine Datei von dieser Domain heruntergeladen haben, ergreifen Sie sofort Maßnahmen. Nachfolgend finden Sie Ressourcen, die Ihnen helfen, den Vorfall zu melden und sich zu schützen.
Melden Sie sich bei Ihren örtlichen Behörden
Wählen Sie Ihr Land aus, um Offizielle Kontakte im Bereich Cyberkriminalität oder einen Beschwerdeentwurf erstellen → zu erhalten.
Jede beliebige Domain prüfen
Bedrohungsanalyse anhand gespeicherter Blocklisten, WHOIS, DNS und öffentlicher Scan-Beweise
Jetzt scannenPhishing melden
Melden Sie verdächtige Domains an unsere Bedrohungsdatenbank – schützen Sie die Community
MeldenEchtzeit-Bedrohungsfeed
Aktuelle Phishing-Meldungen und beobachtete Verfügbarkeitsänderungen
ÜberwachenBleiben Sie auf dem Laufenden, bleiben Sie sicher
Beobachten Sie aktuelle Bedrohungen oder legen Sie Widerspruch gegen diesen Eintrag ein, wenn Sie der Meinung sind, dass es sich um einen Fehlalarm handelt