t-mobile[.]qozas[.]cc
“Welcome to nginx!”
This domain, t-mobile.qozas.cc, is flagged as a brand impersonation threat specifically targeting X.com, a prominent social media platform. Analysis indicates the site was designed to mimic legitimate X.com authentication pages, likely to harvest user credentials or propagate further malicious activity. The absence of a known cryptocurrency drainer kit suggests the primary objective was credential theft rather than direct financial exploitation. The domain exhibits characteristics consistent with large-scale impersonation campaigns, including the use of a subdomain structure to lend false legitimacy through association with unrelated brands like T-Mobile. Technical indicators reveal the domain was registered on February 21, 2026, through Dominet (HK) Limited, a registrar frequently associated with high-risk domains. It resolves to the IP address 47.253.81.117, hosted under AS45102 (Alibaba (US) Technology Co., Ltd.), with a geolocation in the United States. Detection metrics show the domain is flagged by 18 out of 95 security vendors on VirusTotal, while appearing on a single security blocklist. The page title, 'Welcome to nginx!', suggests either an incomplete deployment or a placeholder configuration, which may indicate the campaign was disrupted before full operational capacity was achieved. No SSL certificate was detected, further reducing the domain's perceived legitimacy. As of the latest assessment, t-mobile.qozas.cc has been taken offline, likely due to enforcement actions or infrastructure takedowns. Despite its current inactive status, the domain remains a residual risk due to potential reuse or repurposing by threat actors. Organizations and users are advised to monitor for similar impersonation patterns, particularly those leveraging subdomains of unrelated brands to evade detection. Network defenders should implement strict domain reputation filtering, while end-users should verify URLs through official channels before entering credentials. The elevated risk level is retained due to the domain's recent activity and the persistent threat posed by brand impersonation campaigns targeting high-profile platforms.
Network Security Intelligence
Threat Response Pipeline
Public Blocklist Status
VirusTotal Analysis
Evidence & External Reports
PD-20260203-96C686 Recipient: domainabuse@service.aliyun.com Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive