t-mobile[.]njkh[.]cc
“Welcome to nginx!”
t-mobile.njkh.cc — Contenu indisponible (HTTP 502). Résumé des preuves: VirusTotal 11/95 (Cluster25, CRDF, ESET, Forcepoint ThreatSeeker, Fortinet); URLQuery 2 alerts; PhishDestroy score 87/100. Bureau d’enregistrement: Gname.
L’analyse détaillée de PhishDestroy AI reste en anglais afin de préserver le relevé forensique original.
This domain, t-mobile.njkh.cc, was identified as a brand impersonation threat targeting x.com. As of July 24, 2026, the domain is offline and not actively hosting any content. Analysis indicates that 11 of 95 security vendors on VirusTotal flagged this domain as malicious, suggesting a moderate level of threat recognition. The domain has a Gridinsoft trust score of 0 out of 100, indicating a complete lack of trustworthiness. The domain is registered through Gname.com Pte. Ltd. and is currently blocked by the PhishDestroy service, which adds to the credibility of the threat classification.
The domain's infrastructure is hosted with Cloudflare, Inc. in the United States, and it resolves to the IP address 188.114.96.3. The nameservers used are fiona.ns.cloudflare.com and malcolm.ns.cloudflare.com, which are typical for Cloudflare-hosted domains. The domain was created on February 21, 2026, and does not have an SSL certificate. Upon visiting the domain, the page title displayed is 'Welcome to nginx!', which is the default page often shown when a web server is newly set up or not configured with a specific site.
Given the elevated risk level and the multiple indicators of malicious intent, defenders should treat this domain with caution. While the domain is currently offline, it could be reactivated at any time. It is recommended to monitor for any future activity and consider blocking the domain at the network level to prevent potential phishing attacks. Additionally, organizations should ensure that all users are aware of the threat and trained to recognize and report suspicious links or communications that may impersonate legitimate services.
Renseignements sur la sécurité réseau
Processus de réponse aux menaces Pipeline
Statut de la liste de blocage publique
Analyse VirusTotal
Données factuelles et rapports externes
PD-20260203-357961 Recipient: complaint@gname.com Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif