t-mobile[.]qcuys[.]cc
“Welcome to nginx!”
t-mobile.qcuys.cc — सामग्री अनुपलब्ध (HTTP 502). साक्ष्य सारांश: VirusTotal 12/93 (alphaMountain.ai, Cluster25, CRDF, Emsisoft, Forcepoint ThreatSeeker); URLQuery 4 alerts; PhishDestroy score 86/100. रजिस्ट्रार: Gname.
मूल फॉरेंसिक रिकॉर्ड सुरक्षित रखने के लिए नीचे का विस्तृत PhishDestroy AI विश्लेषण अंग्रेज़ी में रखा गया है।
The domain t-mobile.qcuys.cc was observed being used in a brand‑impersonation campaign targeting the x.com brand. Registration data shows the domain was created on 21 February 2026 through Gname.com Pte. Ltd., and it is hosted on Cloudflare’s network (AS13335) with the IP address 188.114.97.3 located in the United States. DNS resolution is served by the Cloudflare authoritative nameservers amalia.ns.cloudflare.com and elliott.ns.cloudflare.com. No TLS certificate is present; HTTP responses return the default nginx page with the title “Welcome to nginx!”. Malware‑scanning services on VirusTotal recorded 12 positive detections out of 93 submitted security vendors, indicating that a subset of scanners flagged the domain as malicious.
Gridinsoft assigned a trust score of 0 / 100, and the domain appears on at least one external blocklist, confirming its inclusion in threat‑sharing feeds. The PhishDestroy blocklist also lists the domain, and it has been taken offline at the time of reporting. Analysis indicates that the infrastructure is typical of low‑cost phishing operations that leverage Cloudflare’s free DNS and CDN services to hide the true origin of the content. The lack of an SSL certificate suggests that the site was not intended for credential collection over encrypted channels, but the presence of multiple vendor detections and a zero trust score point to malicious intent. The exact payload, landing‑page content, and any credential‑harvesting mechanisms have not been captured, leaving the functional details of the impersonation unknown.
Defenders should add the domain, its IP address, and the associated Cloudflare nameservers to network‑level blocking rules. Monitoring for additional domains registered by the same registrar within a similar time window is advisable. Since the site is already offline, incident response teams should still log the indicator of compromise and correlate it with any recent traffic that may have reached the IP before takedown.
नेटवर्क सुरक्षा इंटेलिजेंस
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | t-mobile.qcuys.cc |
malicious | Sinkholed |
| OpenDNS | t-mobile.qcuys.cc |
phishing | Phishing Block |
| Hagezi Threat Feed | t-mobile.qcuys.cc |
malicious | Sinkholed |
| Quad9 DNS | t-mobile.qcuys.cc |
malicious | Sinkholed |
धमकी प्रतिक्रिया पाइपलाइन
सार्वजनिक ब्लॉकलिस्ट स्थिति
वायरसटोटल विश्लेषण
साक्ष्य और बाहरी रिपोर्टें
PD-20260124-84F111 Recipient: complaint@gname.com क्या आप इस साइट से प्रभावित हुए?
यदि आपने खाता क्रेडेंशियल, व्यक्तिगत या भुगतान जानकारी दर्ज की है, या इस डोमेन से कोई फ़ाइल डाउनलोड की है, तो तुरंत कार्रवाई करें। घटना की रिपोर्ट करने और अपनी सुरक्षा करने में आपकी सहायता के लिए नीचे संसाधन दिए गए हैं।
अपने स्थानीय अधिकारियों को रिपोर्ट करें
आधिकारिक साइबर अपराध संपर्क, या एक शिकायत ड्राफ्ट बनाएं → प्राप्त करने के लिए अपना देश चुनें।
किसी भी डोमेन की जाँच करें
संग्रहीत ब्लॉकलिस्ट, WHOIS, DNS और सार्वजनिक स्कैन साक्ष्य का उपयोग करके खतरे का विश्लेषण
अभी स्कैन करेंफ़िशिंग की रिपोर्ट करें
संदिग्ध डोमेन हमारे थ्रेट डेटाबेस में जमा करें — समुदाय की सुरक्षा करें
रिपोर्ट करेंसीधा खतरा फीड
हाल की फ़िशिंग रिपोर्टें और उपलब्धता में परिवर्तन देखे गए
निगरानी करेंजानकारी में रहें, सुरक्षित रहें
लाइव खतरों की निगरानी करें या यदि आपको लगता है कि यह एक गलत सकारात्मक है तो इस लिस्टिंग को चुनौती दें।