Notification and current-status evidence
The sent-report ledger records the first outgoing report at . A report was sent to the recorded registrar; contact details remain in Domain Intelligence. The latest stored availability evidence still shows the domain reachable; 6 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
t-mobile[.]hpwkg[.]cc
“Welcome to nginx!”
Evidence Summary
The investigated domain, t-mobile.hpwkg.cc, presents a page titled "Welcome to nginx!" while impersonating the brand x.com. This discrepancy indicates a likely phishing or credential harvesting threat, as the site pretends to be a legitimate service but offers no functional content beyond a default web server page.
Technical analysis reveals 21 out of 95 VirusTotal vendors flagged the domain as malicious. It is registered with Gname.com Pte. Ltd., hosted on IP 188.114.97.3 (US) under AS13335 Cloudflare, Inc., and was created on 2026-02-21. SSL certification is from Google Trust Services / WE1, and nameservers are ali.ns.cloudflare.com and rocco.ns.cloudflare.com. The domain is flagged by ADMINUSLabs, Criminal IP, BitDefender, Chong Lua Dao, and Cluster25, with one blocklist entry.
The domain is currently BANNED. Its GridinSoft trust score is 0/100, and the DOM risk score is 10, indicating a critical risk level. Immediate avoidance is recommended.
Submitted Evidence Snapshot
- Sent
- Ledger records
- 1
- Case ID
PD-20260131-E9DBEA- PDF artifact
- PDF evidence
Full evidence text
Policy Violations: Illegal Activities section forbids phishing, fraud, fake sites, malware distribution; registrar investigates and may suspend or delete domain
Applicable Laws: Computer Misuse Act 1993 §§3+, Penal Code §§415–420 (cheating), Online Criminal Harms Act (OCHA)
Data Coverage
Network Security Intelligence
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Quad9 DNS | t-mobile.hpwkg.cc |
malicious | Sinkholed |
| OpenDNS | t-mobile.hpwkg.cc |
phishing | Phishing Block |
| DNS4EU | t-mobile.hpwkg.cc |
malicious | Sinkholed |
| Hagezi Threat Feed | t-mobile.hpwkg.cc |
malicious | Sinkholed |
Threat Response Pipeline
Blocklist coverage
10 monitored external feeds · stored snapshot Aug 12, 2026
10 monitored external feeds No match
Detection timeline
-
Domain status
Reachable → Unreachable
-
Cloudflare Radar
Cloudflare Radar scan stored · Open scan
-
Cloudflare Radar
Cloudflare Radar scan stored · Open scan
-
Domain status
Reachable → Unreachable
-
Domain status
Unreachable → Reachable
-
Domain status
Reachable → Unreachable
-
Domain status
Unreachable → Reachable
VirusTotal Analysis
Site Performance Analysis
Google PageSpeed Insights — mobile performance audit of t-mobile.hpwkg.cc · checked Apr 23, 2026
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive