Aller au rapport de sécurité
Checked 09/08/2026 Ref C19668F8

MALICIOUS — CRITICAL

att[.]psiew[.]cc

This domain, att.psiew.cc, is a confirmed phishing site designed to impersonate x.com, the social media platform.

95/100 evidence score · Critical
VirusTotal
19/93
Blocklists
No stored match
Disponibilité
Contenu indisponible · HTTP 502
Report / Add Evidence Appeal this listing
2026-02-04 23:15 UTCContenu indisponible · HTTP 502

Do not enter credentials, seed phrases, payment details, or personal information on this domain.

⚠️
Ce domaine a été signalé comme malveillant
Moteurs de sécurité signalant une détection : 19. Faites preuve d’une extrême prudence – ne saisissez pas d’informations d’identification ou d’informations personnelles.
Jump to section
Résumé du rapport

att.psiew.cc — Contenu indisponible (HTTP 502). Résumé des preuves: VirusTotal 19/93 (ADMINUSLabs, Criminal IP, BitDefender, Cluster25, CRDF); URLQuery 2 alerts; Google Safe Browsing flagged; PhishDestroy score 95/100. Bureau d’enregistrement: Gname.

L’analyse détaillée de PhishDestroy AI reste en anglais afin de préserver le relevé forensique original.

Evidence Analysis

Ref C19668F8

Is att.psiew.cc a Fake X.com Login Page?

att.psiew.cc is a high-risk phishing domain impersonating x.com, flagged by 19 security vendors. Created February 21, 2026, it poses an active credential theft.

This domain, att.psiew.cc, is a confirmed phishing site designed to impersonate x.com, the social media platform. The site attempts to deceive users into entering their login credentials by mimicking the appearance and functionality of the legitimate x.com login page. Once entered, these credentials are harvested by threat actors for unauthorized account access, financial fraud, or further phishing campaigns targeting the victim's contacts. The site may also distribute malware under the guise of a required software update or verification process, increasing the risk of device compromise and data exfiltration. Analysis indicates this domain was registered on February 21, 2026, through Gname.com Pte. Ltd., a registrar frequently associated with malicious domains. The site resolves to the IP address 104.21.94.40, hosted on Cloudflare’s infrastructure (AS13335), which is commonly abused to mask the true origin of phishing operations. At the time of assessment, 19 out of 95 security vendors on VirusTotal flagged this domain as malicious, with detections including phishing, brand impersonation, and fraudulent activity. The domain appears on one security blocklist, and Google Safe Browsing has explicitly labeled it as a phishing threat. Notably, the site lacks an SSL certificate, which is unusual for legitimate login portals and serves as a red flag for users. The page title, 'Welcome to nginx!', suggests misconfigured or hastily deployed server infrastructure, further indicating malicious intent. If you or someone in your organization visited att.psiew.cc, immediate action is required to mitigate potential damage. First, do not enter any credentials or personal information on the site. If credentials were already submitted, assume they are compromised and reset passwords for x.com and any other accounts using the same credentials. Enable multi-factor authentication (MFA) on all critical accounts to prevent unauthorized access. Scan the device used to access the site for malware using updated security software, as phishing pages may deploy malicious payloads. Monitor accounts for suspicious activity, such as unauthorized posts, messages, or password change requests. Report the incident to your organization’s security team or a trusted cybersecurity professional for further investigation. Additionally, consider reporting the domain to the registrar (Gname.com Pte. Ltd.) and hosting provider (Cloudflare) to aid in takedown efforts and prevent further abuse.

Stored source results

Recorded verdicts and infrastructure observations for this domain.

VirusTotal
VirusTotal
19 det.
URLQuery
URLQuery
2 threat alerts
URLScan
URLScan
Statut observé
Contenu indisponible 502
PhishDestroy
DestroyList
Répertorié
Reports Sent
1
Couverture des données12 recorded checks
VirusTotal 19 / 93 URLQuery 2 threat-system alerts PhishStats checked — no match recorded OTX no community references CF Radar scan completed URLScan capture rapport stocké URLScan verdict verdict indisponible Blocs DNS pas vérifié TLS aucune donnée de certificat WHOIS not parsed Capture d'écran 3 captures · 3 sources Chaîne de redirection non sondé
Renseignements sur la sécurité réseau
Threat Detection Systems 2 alerts
Detection System Indicator Verdict Alert
DNS4EU att.psiew.cc malicious Sinkholed
Cloudflare DNS att.psiew.cc malicious Sinkholed

Processus de réponse aux menaces Pipeline

Découverte
Checks
Reports
Disponibilité
12/12
Sent Report Recorded
Stored sent-report record for registrar Gname.com Pte. Ltd., hosting provider, 1 abuse contact
complaint@gname.com
05/02/2026

Statut de la liste de blocage publique

Capture enregistrée

Informations sur les domaines

Domaine
Google Safe Browsing Marqué Social engineering checked 25/02/2026
Serveur / ASN cloudflare · AS13335 Cloudflare, Inc.
IP Context Cloudflare shared edge origin IP hidden La réputation Edge-IP n’est pas attribuée à ce domaine.
Registrar (base domain) Gname SG(SG)
Adresse IP 104.21.94.40 CDN
LocalisationUS San Francisco, US
RéseauAS13335 · Cloudflare, Inc.
L'adresse IP d'origine est cachée derrière un proxy CDN. Les résultats d’IP inversé pour l’adresse périphérique contiennent des locataires non liés ; trouver l’origine nécessite un DNS passif ou des données de transparence des certificats.
Registration (base domain)psiew.cc · Expires 02/02/2027
Statut HTTP502 Error
Délai avant la première indisponibilité 99 days
Ce que nous comptons Temps écoulé entre le premier rapport d'abus stocké et la première observation indiquant que le contenu n'était pas disponible. Cela n’établit pas la cause.
Ce que contient chaque rapport Les enregistrements de rapports sortants stockés peuvent faire référence à des preuves disponibles à ce moment-là, telles que les verdicts des fournisseurs, les données d'enregistrement, les détails d'hébergement, les classifications ou les captures d'écran. Cette page ne déduit pas la charge utile exacte livrée, la réception, l'accusé de réception ou l'action d'un destinataire.
Détails techniquesDNS, SAN SSL, horodatages
Première détection05/02/2026
DOM Analysisanalyzed 23/04/2026score 10/100
IoC Extractionscanned 02/08/20260 wallet · 0 Telegram IoCs
Submitted URLhttp://att.psiew.cc/
Serveurs de nomsbenedict.ns.cloudflare.commelinda.ns.cloudflare.com
TLS Observationvalid from 02/02/2026scanned 15/03/2026
Case ID
Titre de la page
Welcome to nginx!
Signaler ce domaine Envoyez des éléments de preuve et contribuez à protéger les autres

Analyse VirusTotal

19 / Les fournisseurs de sécurité 93 ont signalé ce domaine
View on VT
Last analyzed
ADMINUSLabs
Criminal IP
BitDefender
Cluster25
CRDF
CyRadar
DNS8
ESET
Forcepoint ThreatSeeker
Fortinet
G-Data
Google Safebrowsing
Gridinsoft
Lionic
Seclookup
SOCRadar
Sophos
VIPRE
Webroot
Données factuelles et rapports externesIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
If credentials were compromised, report immediately. Do not engage with recovery scammers.

Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.

Europol
Trouvez le canal de signalement officiel pour votre pays de l'UE
National police directory
Méfiez-vous des escrocs qui prétendent vous aider à récupérer vos biens ! Les criminels peuvent recontacter leurs victimes tout en se faisant passer pour des enquêteurs, des avocats ou des agents de recouvrement. Ne payez pas de frais initiaux et ne partagez pas vos informations d'identification. En savoir plus sur la fraude liée aux aides à la reprise →

Signalez-le à vos autorités locales

Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.

Annuaire de 97 pays
Brouillon assisté par l'IA : les détails de l'incident sont traités par le fournisseur d'IA Examinez-le et soumettez-le vous-même
Intégrer ce rapportRead-only HTML widget
HTML · IFRAME

Intégrer ce rapport

Partagez ces informations sur les menaces sur votre site web ou votre blog

embed.html
<iframe
  src="https://phishdestroy.io/fr/embed/domain/att.psiew.cc"
  title="PhishDestroy threat report for att.psiew.cc"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>