t-mobile[.]tvgha[.]cc
“Welcome to nginx!”
t-mobile.tvgha.cc — Contenido no disponible (HTTP 502). Resumen de las pruebas: VirusTotal 20/95 (ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, Cluster25); URLQuery 1 alert; PhishDestroy score 95/100. Registrador: Gname.
El análisis detallado de PhishDestroy AI se mantiene en inglés para conservar el registro forense original.
This domain, t-mobile.tvgha.cc, is identified as a brand impersonation threat designed to mimic X.com, formerly Twitter. The site likely presented a counterfeit login portal to harvest user credentials, session tokens, or other sensitive authentication details. Brand impersonation pages often employ visual mimicry—such as cloned logos, color schemes, and interface layouts—to deceive visitors into believing they are interacting with a legitimate service. In this case, the domain name itself attempts to exploit trust in the T-Mobile brand while redirecting users to a fraudulent X.com login interface, increasing the likelihood of successful credential theft. Analysis indicates the domain was registered on February 21, 2026, through Gname.com Pte. Ltd., a registrar frequently associated with high-risk domains. The site resolved to the IP address 104.21.13.125, hosted on Cloudflare’s network (AS13335), which is commonly used to mask the true origin of malicious infrastructure. At the time of assessment, the domain displayed the default page title “Welcome to nginx!,” suggesting either an incomplete deployment or an attempt to evade detection by presenting minimal content. VirusTotal reports 20 out of 95 security vendors flagging the domain as malicious, while it appears on one security blocklist. The absence of an SSL certificate further undermines any semblance of legitimacy, as modern web services universally enforce HTTPS for secure communication. If you visited t-mobile.tvgha.cc or entered any login credentials, immediate action is required. First, revoke access to any active sessions on X.com by visiting the platform’s security settings and logging out of all devices. Reset your X.com password using a strong, unique passphrase, and enable multi-factor authentication if not already active. Monitor your account for unauthorized activity, including posts, direct messages, or linked applications you did not authorize. If financial information or payment methods were exposed, contact your bank or card issuer to report potential fraud. Finally, scan your device for malware using updated security tools, as some phishing pages may attempt to deliver secondary payloads. Avoid reusing passwords across services, and verify the authenticity of any domain before entering credentials.
Inteligencia de seguridad de red
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | t-mobile.tvgha.cc |
malicious | Sinkholed |
Proceso de respuesta ante amenazas Pipeline
Estado de la lista de bloqueados pública
Análisis de VirusTotal
Datos y informes externos
PD-20260203-FB4EC7 Recipient: complaint@gname.com ¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.