t-mobile.vwukq[.]cc
Forensic brief
PhishDestroy identifies t-mobile.vwukq.cc as a high-risk generic phishing domain actively targeting users. The domain attempts to impersonate legitimate services, potentially to steal sensitive data such as credentials or personal information. Evidence supporting the threat includes the domain’s recent creation date on February 21, 2026, its continued active status, and resolution to IP address 104.21.70.248. VirusTotal flags this domain by 12 out of 95 security vendors, and it appears on one security blocklist, reinforcing its malicious reputation. The landing page currently displays a generic 'Welcome to nginx!' message, which may be used as a placeholder or to evade immediate detection. Users are advised to avoid visiting t-mobile.vwukq.cc and to verify URLs before submitting any personal information. PhishDestroy continues to monitor this domain, and organizations should consider blocking it at the network level to prevent potential compromise. Remain vigilant and report suspicious domains promptly.
Threat response pipeline
VirusTotal
Forensic Evidence CollectionEvidence capture
Domain Intelligence
Technical details
Public blocklist status
VirusTotal consensus
Aggregated detection across 12 security vendors.
Evidence & external reports
Were you affected by this site?
Were You Affected?
Recommendations & Advice for Victims
- Do not pay anything else. Recovery agents demanding upfront fees are a second-stage scam.
- Disconnect compromised wallets. Move remaining funds to a fresh seed phrase generated offline.
- Preserve evidence. Screenshot transactions, save URLs, archive emails — chain-of-custody matters for prosecution.
- Report to authorities (see section 15 below) — even small reports help build case patterns.
- Notify your bank/exchange. Some chargebacks may still be possible within 24-72h.
Report to your local authorities
Email template — registrar abuse
abuse@
Case: PD-
Embed this report
About this report
About this report: t-mobile.vwukq.cc
This domain security report is maintained by PhishDestroy's automated threat-intelligence pipeline. Our system continuously monitors this domain across 12 security vendors on VirusTotal and 1 public blocklists.
The site displays a page titled “Welcome to nginx!”.
t-mobile.vwukq.cc has been flagged by 12 security vendors as of May 17, 2026.
If you believe this listing is inaccurate, you can submit an appeal. For more information about our methodology, visit our FAQ page.