t-mobile[.]tvgha[.]cc
“Welcome to nginx!”
t-mobile.tvgha.cc — Inhalt nicht verfügbar (HTTP 502). Zusammenfassung der Beweislage: VirusTotal 20/95 (ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, Cluster25); URLQuery 1 alert; PhishDestroy score 95/100. Registrar: Gname.
Die ausführliche Analyse von PhishDestroy AI bleibt auf Englisch, damit der ursprüngliche forensische Bericht unverändert bleibt.
This domain, t-mobile.tvgha.cc, is identified as a brand impersonation threat designed to mimic X.com, formerly Twitter. The site likely presented a counterfeit login portal to harvest user credentials, session tokens, or other sensitive authentication details. Brand impersonation pages often employ visual mimicry—such as cloned logos, color schemes, and interface layouts—to deceive visitors into believing they are interacting with a legitimate service. In this case, the domain name itself attempts to exploit trust in the T-Mobile brand while redirecting users to a fraudulent X.com login interface, increasing the likelihood of successful credential theft. Analysis indicates the domain was registered on February 21, 2026, through Gname.com Pte. Ltd., a registrar frequently associated with high-risk domains. The site resolved to the IP address 104.21.13.125, hosted on Cloudflare’s network (AS13335), which is commonly used to mask the true origin of malicious infrastructure. At the time of assessment, the domain displayed the default page title “Welcome to nginx!,” suggesting either an incomplete deployment or an attempt to evade detection by presenting minimal content. VirusTotal reports 20 out of 95 security vendors flagging the domain as malicious, while it appears on one security blocklist. The absence of an SSL certificate further undermines any semblance of legitimacy, as modern web services universally enforce HTTPS for secure communication. If you visited t-mobile.tvgha.cc or entered any login credentials, immediate action is required. First, revoke access to any active sessions on X.com by visiting the platform’s security settings and logging out of all devices. Reset your X.com password using a strong, unique passphrase, and enable multi-factor authentication if not already active. Monitor your account for unauthorized activity, including posts, direct messages, or linked applications you did not authorize. If financial information or payment methods were exposed, contact your bank or card issuer to report potential fraud. Finally, scan your device for malware using updated security tools, as some phishing pages may attempt to deliver secondary payloads. Avoid reusing passwords across services, and verify the authenticity of any domain before entering credentials.
Erkenntnisse zur Netzwerksicherheit
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | t-mobile.tvgha.cc |
malicious | Sinkholed |
Pipeline zur Reaktion auf Sicherheitsbedrohungen
Status der öffentlichen Sperrliste
VirusTotal-Analyse
Nachweise und externe Berichte
PD-20260203-FB4EC7 Recipient: complaint@gname.com Wurden Sie von dieser Website betroffen?
Wenn Sie Kontoanmeldeinformationen, persönliche oder Zahlungsinformationen eingegeben oder eine Datei von dieser Domain heruntergeladen haben, ergreifen Sie sofort Maßnahmen. Nachfolgend finden Sie Ressourcen, die Ihnen helfen, den Vorfall zu melden und sich zu schützen.
Melden Sie sich bei Ihren örtlichen Behörden
Wählen Sie Ihr Land aus, um Offizielle Kontakte im Bereich Cyberkriminalität oder einen Beschwerdeentwurf erstellen → zu erhalten.
Jede beliebige Domain prüfen
Bedrohungsanalyse anhand gespeicherter Blocklisten, WHOIS, DNS und öffentlicher Scan-Beweise
Jetzt scannenPhishing melden
Melden Sie verdächtige Domains an unsere Bedrohungsdatenbank – schützen Sie die Community
MeldenEchtzeit-Bedrohungsfeed
Aktuelle Phishing-Meldungen und beobachtete Verfügbarkeitsänderungen
ÜberwachenBleiben Sie auf dem Laufenden, bleiben Sie sicher
Beobachten Sie aktuelle Bedrohungen oder legen Sie Widerspruch gegen diesen Eintrag ein, wenn Sie der Meinung sind, dass es sich um einen Fehlalarm handelt