att[.]lydbt[.]cc
“Welcome to nginx!”
साक्ष्य सारांश
The domain att.lydbt.cc was registered on 21 February 2026 through Gname.com Pte. Ltd. and is currently listed as offline. DNS resolution points to 188.114.96.3, an address owned by Cloudflare, Inc. (AS13335) and geolocated to the United States. The authoritative name servers are henry.ns.cloudflare.com and ulla.ns.cloudflare.com, indicating that the infrastructure is hosted behind Cloudflare’s CDN. No TLS certificate is presented; HTTP requests receive the default “Welcome to nginx!” page title, suggesting the server is delivering a generic web server response rather than a targeted login portal. Threat intelligence shows the domain is classified as a brand‑impersonation campaign targeting x.com.
VirusTotal analysis flagged the domain in 12 of 93 vendor engines, and the Gridinsoft trust score is 0 / 100, reflecting a high confidence of malicious intent. The domain appears on a single external blocklist and has been actively blocked by PhishDestroy. The lack of a valid SSL certificate, combined with the generic nginx title, may be an attempt to evade automated content inspection while retaining the ability to host malicious payloads. Uncertainty remains regarding the specific payload or phishing page content because no detailed page scrape is available. Analysts cannot confirm whether credential‑stealing forms or redirect chains were present before the takedown.
The presence of Cloudflare as the front‑end service does not reveal the origin of any back‑end server that may have hosted malicious code. Defenders should add att.lydbt.cc to URL filtering rules, block the associated IP address 188.114.96.3, and monitor for any new subdomains under the same registrar or name‑server pair. Continuous observation of Cloudflare‑originating traffic for anomalous request patterns is advised. Updating endpoint protection and email security gateways with the observed VirusTotal detection signatures will help reduce exposure to any future re‑use of this infrastructure.
भेजे गए प्रमाण का स्नैपशॉट
- भेजा गया
- लेज़र रिकॉर्ड
- 1
- केस आईडी
PD-20260119-5FDDD7- PDF दस्तावेज़
- PDF प्रमाण
प्रमाण का पूरा पाठ
Policy Violations: Illegal Activities section forbids phishing, fraud, fake sites, malware distribution; registrar investigates and may suspend or delete domain
Applicable Laws: Computer Misuse Act 1993 §§3+, Penal Code §§415–420 (cheating), Online Criminal Harms Act (OCHA)
Data Coverage
नेटवर्क सुरक्षा इंटेलिजेंस
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| OpenDNS | att.lydbt.cc |
phishing | Phishing Block |
| DNS4EU | att.lydbt.cc |
malicious | Sinkholed |
| Hagezi Threat Feed | att.lydbt.cc |
malicious | Sinkholed |
धमकी प्रतिक्रिया पाइपलाइन
ब्लॉकलिस्ट कवरेज
10 निगरानी वाले बाहरी स्रोत · संग्रहीत स्नैपशॉट 12/08/2026
पहचान समयरेखा
-
Cloudflare Radar
Cloudflare Radar स्कैन संग्रहीत · स्कैन खोलें
वायरसटोटल विश्लेषण
क्या आप इस साइट से प्रभावित हुए?
यदि आपने खाता क्रेडेंशियल, व्यक्तिगत या भुगतान जानकारी दर्ज की है, या इस डोमेन से कोई फ़ाइल डाउनलोड की है, तो तुरंत कार्रवाई करें। घटना की रिपोर्ट करने और अपनी सुरक्षा करने में आपकी सहायता के लिए नीचे संसाधन दिए गए हैं।
अपने स्थानीय अधिकारियों को रिपोर्ट करें
आधिकारिक साइबर अपराध संपर्क, या एक शिकायत ड्राफ्ट बनाएं → प्राप्त करने के लिए अपना देश चुनें।
किसी भी डोमेन की जाँच करें
संग्रहीत ब्लॉकलिस्ट, WHOIS, DNS और सार्वजनिक स्कैन साक्ष्य का उपयोग करके खतरे का विश्लेषण
अभी स्कैन करेंफ़िशिंग की रिपोर्ट करें
संदिग्ध डोमेन हमारे थ्रेट डेटाबेस में जमा करें — समुदाय की सुरक्षा करें
रिपोर्ट करेंसीधा खतरा फीड
हाल की फ़िशिंग रिपोर्टें और उपलब्धता में परिवर्तन देखे गए
निगरानी करेंजानकारी में रहें, सुरक्षित रहें
लाइव खतरों की निगरानी करें या यदि आपको लगता है कि यह एक गलत सकारात्मक है तो इस लिस्टिंग को चुनौती दें।