Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is complaint@gname.com.
The latest stored availability evidence still shows the domain reachable; 6 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
t-mobile[.]lfdis[.]cc
“Welcome to nginx!”
t-mobile.lfdis.cc — No verificado. Resumen de las pruebas: VirusTotal 15/91 (ADMINUSLabs, Criminal IP, BitDefender, Chong Lua Dao, CyRadar); URLQuery 2 alerts; CF Radar malicious; PhishDestroy score 95/100. Registrador: Gname.
El análisis detallado de PhishDestroy AI se mantiene en inglés para conservar el registro forense original.
The domain t-mobile.lfdis.cc has been confirmed as a brand impersonation site targeting x.com. Analysis indicates this domain was operational as a fraudulent replica of the legitimate platform, likely designed to deceive users into disclosing credentials or sensitive information. The domain is currently offline, though its infrastructure remains a potential vector for future malicious activity. Infrastructure analysis reveals the domain was registered through Gname.com Pte. Ltd. on February 21, 2026, and resolved to the IP address 172.67.195.210, hosted on Cloudflare’s network (AS13335). Security vendors flagged the domain on VirusTotal, with 19 of 95 engines detecting malicious indicators. The domain appeared on one security blocklist and was actively blocked by PhishDestroy. The observed page title, 'Welcome to nginx!', suggests default server configuration, often indicative of hastily deployed phishing infrastructure. The SSL certificate was issued by Google Trust Services (WE1), a common tactic to lend false legitimacy to fraudulent sites. The domain is currently offline, reducing immediate risk to users. However, organizations should monitor for reactivation or similar domains leveraging the same registrar or hosting provider. Network defenders are advised to block the domain and associated IP address at the perimeter. Endpoint protection systems should be updated to include this domain in threat intelligence feeds. Users who may have interacted with the site should reset credentials for x.com and enable multi-factor authentication as a precautionary measure.
Inteligencia de seguridad de red
Proceso de respuesta ante amenazas Pipeline
Estado de la lista de bloqueados pública
Tecnologías · 2 identified
Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100 % de confianzaHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100 % de confianzaAnálisis de VirusTotal
Evidencias archivadas
Análisis del rendimiento del sitio
Google PageSpeed Insights — mobile performance audit of t-mobile.lfdis.cc · checked Apr 23, 2026
Datos y informes externos
PD-20260202-326674 Recipient: complaint@gname.com ¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.