t-mobile[.]qarhj[.]cc
“Welcome to nginx!”
t-mobile.qarhj.cc — Contenido no disponible (HTTP 502). Resumen de las pruebas: VirusTotal 19/93 (ADMINUSLabs, Criminal IP, alphaMountain.ai, BitDefender, Cluster25); URLQuery 4 alerts; Spamhaus DBL_PHISH; PhishDestroy score 95/100. Registrador: Dominet (HK).
El análisis detallado de PhishDestroy AI se mantiene en inglés para conservar el registro forense original.
This domain, t-mobile.qarhj.cc, is flagged for brand impersonation, specifically targeting x.com. Analysis indicates no direct evidence of a crypto drainer or credential theft kit, but the infrastructure aligns with known patterns of brand misuse. The page title, 'Welcome to nginx!', suggests a default server configuration, often indicative of hastily deployed malicious infrastructure or misconfigured phishing pages. No SSL certificate is present, increasing the likelihood of interception or tampering during data transmission. Infrastructure analysis reveals the following technical indicators: the domain resolves to IP address 8.219.239.111, hosted on Alibaba (US) Technology Co., Ltd. infrastructure (AS45102) in Singapore. It was registered on January 14, 2026, through Dominet (HK) Limited, a registrar frequently associated with high-risk domains. VirusTotal reports 19 out of 95 security vendors flagging the domain as malicious, and it appears on one security blocklist. No Google Safe Browsing (GSB) detection is noted at this time, though this may reflect a lag in reporting rather than a clean status. The domain is currently offline, likely taken down due to detection or enforcement actions. However, the elevated risk persists due to the domain's recent creation date and association with a known brand impersonation campaign. Organizations should monitor for re-registration or similar domains under the same registrar or IP range. Network defenders are advised to block the resolved IP and domain at the perimeter, while end users should verify the legitimacy of any communication purporting to originate from x.com. The absence of SSL and the use of a default nginx page further underscore the need for heightened scrutiny of this infrastructure.
Inteligencia de seguridad de red
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| OpenDNS | t-mobile.qarhj.cc |
phishing | Phishing Block |
| Quad9 DNS | t-mobile.qarhj.cc |
malicious | Sinkholed |
| Hagezi Threat Feed | t-mobile.qarhj.cc |
malicious | Sinkholed |
| DNS4EU | t-mobile.qarhj.cc |
malicious | Sinkholed |
Proceso de respuesta ante amenazas Pipeline
Estado de la lista de bloqueados pública
Análisis de VirusTotal
Datos y informes externos
PD-20260119-20AB7B Recipient: domainabuse@service.aliyun.com ¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.