att[.]qatio[.]cc
Análisis de phishing y seguridad de att.qatio.cc
“Welcome to nginx!”
att.qatio.cc — Contenido no disponible (HTTP 502). Resumen de las pruebas: VirusTotal 12/95 (Criminal IP, Cluster25, CRDF, CyRadar, Forcepoint ThreatSeeker); URLQuery 4 alerts; PhishDestroy score 86/100. Registrador: Gname.
El análisis detallado de PhishDestroy AI se mantiene en inglés para conservar el registro forense original.
Analysis of the domain att.qatio.cc shows a newly registered site created on February 21, 2026 that has been taken offline as of the report date. The domain resolves to the IP address 172.67.161.61, which belongs to the Cloudflare network (AS13335) and is geolocated in the United States. Nameserver records point to henry.ns.cloudflare.com and ulla.ns.cloudflare.com, confirming the use of Cloudflare’s DNS infrastructure. The registrar listed is Gname.com Pte. Ltd. No TLS certificate is presented; the HTTP response returns the default "Welcome to nginx!" page title, indicating that no custom web content was observed before the takedown.
Threat intelligence flags the site as a brand‑impersonation campaign targeting x.com. Twelve of ninety‑five VirusTotal scanners flagged the domain, and it appears on a single external blocklist. The Gridinsoft trust score is 0 out of 100, reinforcing the malicious assessment. PhishDestroy has already blocked the domain, and the current status is offline, suggesting the operators have withdrawn the site, possibly to avoid further detection.
Uncertainty remains around any payload or credential‑harvesting infrastructure that may have been hosted behind the domain before takedown, as no further page content or redirects were captured. Defenders should continue to block the IP 172.67.161.61 at the network perimeter, add att.qatio.cc to local and cloud‑based URL filtering lists, and monitor for re‑registration of similar sub‑domains under the same registrar or using the same Cloudflare nameservers. Ongoing scrutiny of Cloudflare‑hosted assets targeting the x.com brand is advised, as the infrastructure could be repurposed for future impersonation attempts.
Inteligencia de seguridad de red
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| OpenDNS | att.qatio.cc |
phishing | Phishing Block |
| DNS4EU | att.qatio.cc |
malicious | Sinkholed |
| Hagezi Threat Feed | att.qatio.cc |
malicious | Sinkholed |
| Quad9 DNS | att.qatio.cc |
malicious | Sinkholed |
Proceso de respuesta ante amenazas Pipeline
Estado de la lista de bloqueados pública
Análisis de VirusTotal
Datos y informes externos
PD-20260119-2A0D31 Recipient: complaint@gname.com ¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.