att[.]mrqvs[.]cc
“Welcome to nginx!”
साक्ष्य सारांश
The domain att.mrqvs.cc was registered on February 21, 2026 through Gname.com Pte. Ltd. and is currently listed as offline. DNS resolution points to the IP address 188.114.97.3, which belongs to the Cloudflare network (AS13335, United States). The domain is served by two Cloudflare authoritative nameservers, alfred.ns.cloudflare.com and nancy.ns.cloudflare.com, indicating that the attacker leveraged Cloudflare’s DNS and CDN services to obscure the true hosting location. No SSL certificate is presented, and an HTTP request returns the default "Welcome to nginx!" page, confirming the presence of a generic web server with no TLS encryption.
Security intelligence flags the site as a brand impersonation campaign targeting the brand x.com. The Gridinsoft trust score is 0 out of 100, reflecting a maximum risk rating. The domain appears on a single external blocklist, specifically PhishDestroy, which has actively blocked the host. VirusTotal analysis shows that 14 of 95 scanning engines identified the domain as malicious, providing independent vendor corroboration of its illicit nature.
While the available data confirms the infrastructure, the specific payload, phishing kit, or compromised credentials have not been observed, leaving the exact attack vector uncertain. Defenders should immediately add att.mrqvs.cc to network deny lists and block the associated IP 188.114.97.3 at perimeter firewalls. Continuous monitoring of Cloudflare‑associated IP ranges for similar patterns is advised, as the attacker may repurpose the same CDN edge for future campaigns. Future investigations should request full page content, capture any redirected URLs, and verify whether the domain was ever configured with TLS to assess potential credential harvesting tactics.
भेजे गए प्रमाण का स्नैपशॉट
- भेजा गया
- लेज़र रिकॉर्ड
- 1
- केस आईडी
PD-20260120-8B6E79- कैप्चर किए गए पेज का शीर्षक
- Welcome to nginx!
- PDF दस्तावेज़
- PDF प्रमाण
प्रमाण का पूरा पाठ
Policy Violations: Illegal Activities section forbids phishing, fraud, fake sites, malware distribution; registrar investigates and may suspend or delete domain
Applicable Laws: Computer Misuse Act 1993 §§3+, Penal Code §§415–420 (cheating), Online Criminal Harms Act (OCHA)
Data Coverage
नेटवर्क सुरक्षा इंटेलिजेंस
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | att.mrqvs.cc |
malicious | Sinkholed |
धमकी प्रतिक्रिया पाइपलाइन
ब्लॉकलिस्ट कवरेज
10 निगरानी वाले बाहरी स्रोत · संग्रहीत स्नैपशॉट 12/08/2026
पहचान समयरेखा
-
Cloudflare Radar
Cloudflare Radar स्कैन संग्रहीत · स्कैन खोलें
वायरसटोटल विश्लेषण
क्या आप इस साइट से प्रभावित हुए?
यदि आपने खाता क्रेडेंशियल, व्यक्तिगत या भुगतान जानकारी दर्ज की है, या इस डोमेन से कोई फ़ाइल डाउनलोड की है, तो तुरंत कार्रवाई करें। घटना की रिपोर्ट करने और अपनी सुरक्षा करने में आपकी सहायता के लिए नीचे संसाधन दिए गए हैं।
अपने स्थानीय अधिकारियों को रिपोर्ट करें
आधिकारिक साइबर अपराध संपर्क, या एक शिकायत ड्राफ्ट बनाएं → प्राप्त करने के लिए अपना देश चुनें।
किसी भी डोमेन की जाँच करें
संग्रहीत ब्लॉकलिस्ट, WHOIS, DNS और सार्वजनिक स्कैन साक्ष्य का उपयोग करके खतरे का विश्लेषण
अभी स्कैन करेंफ़िशिंग की रिपोर्ट करें
संदिग्ध डोमेन हमारे थ्रेट डेटाबेस में जमा करें — समुदाय की सुरक्षा करें
रिपोर्ट करेंसीधा खतरा फीड
हाल की फ़िशिंग रिपोर्टें और उपलब्धता में परिवर्तन देखे गए
निगरानी करेंजानकारी में रहें, सुरक्षित रहें
लाइव खतरों की निगरानी करें या यदि आपको लगता है कि यह एक गलत सकारात्मक है तो इस लिस्टिंग को चुनौती दें।