t-mobile[.]sgriv[.]cc
“Welcome to nginx!”
t-mobile.sgriv.cc — सामग्री अनुपलब्ध (HTTP 502). साक्ष्य सारांश: VirusTotal 10/93 (alphaMountain.ai, Cluster25, CRDF, CyRadar, Emsisoft); PhishDestroy score 80/100.
मूल फॉरेंसिक रिकॉर्ड सुरक्षित रखने के लिए नीचे का विस्तृत PhishDestroy AI विश्लेषण अंग्रेज़ी में रखा गया है।
Analysis of t-mobile.sgriv.cc, a domain created on February 21, 2026, indicates elevated risk due to confirmed brand‑impersonation activity targeting x.com. The domain resolves to IP address 172.67.171.149, which belongs to Cloudflare, Inc. (AS13335) and is geolocated in the United States. Public blocklist data shows the domain appears on one security blocklist and is specifically listed by PhishDestroy as a malicious entry. Gridinsoft assigns a trust score of 0 out of 100, reflecting the lowest possible confidence in legitimacy.
The only observed HTTP response returns the generic page title "Welcome to nginx!", offering no additional context about the payload or user‑facing content. SSL inspection reveals the certificate labeled "WE1", which does not correspond to a recognized corporate or extended validation certificate, further supporting suspicious status. VirusTotal analysis records ten detections out of ninety‑three participating security vendors, confirming that multiple independent scanners have flagged the domain as malicious. Although the site is currently taken offline, the combination of brand impersonation classification, low trust score, blocklist inclusion, and multiple vendor detections suggests a high likelihood of phishing or credential‑stealing intent.
Defenders should continue to block the domain at perimeter firewalls, update URL filtering policies to include the observed IP range, and monitor for any re‑hosting attempts that might reuse the same certificate or page title. Incident response teams should also correlate any internal logs for outbound connections to 172.67.171.149, especially from users accessing x.com, to identify potential exposure. Ongoing vigilance is advised until the domain remains permanently offline.
धमकी प्रतिक्रिया पाइपलाइन
सार्वजनिक ब्लॉकलिस्ट स्थिति
वायरसटोटल विश्लेषण
साक्ष्य और बाहरी रिपोर्टें
क्या आप इस साइट से प्रभावित हुए?
यदि आपने खाता क्रेडेंशियल, व्यक्तिगत या भुगतान जानकारी दर्ज की है, या इस डोमेन से कोई फ़ाइल डाउनलोड की है, तो तुरंत कार्रवाई करें। घटना की रिपोर्ट करने और अपनी सुरक्षा करने में आपकी सहायता के लिए नीचे संसाधन दिए गए हैं।
अपने स्थानीय अधिकारियों को रिपोर्ट करें
आधिकारिक साइबर अपराध संपर्क, या एक शिकायत ड्राफ्ट बनाएं → प्राप्त करने के लिए अपना देश चुनें।
किसी भी डोमेन की जाँच करें
संग्रहीत ब्लॉकलिस्ट, WHOIS, DNS और सार्वजनिक स्कैन साक्ष्य का उपयोग करके खतरे का विश्लेषण
अभी स्कैन करेंफ़िशिंग की रिपोर्ट करें
संदिग्ध डोमेन हमारे थ्रेट डेटाबेस में जमा करें — समुदाय की सुरक्षा करें
रिपोर्ट करेंसीधा खतरा फीड
हाल की फ़िशिंग रिपोर्टें और उपलब्धता में परिवर्तन देखे गए
निगरानी करेंजानकारी में रहें, सुरक्षित रहें
लाइव खतरों की निगरानी करें या यदि आपको लगता है कि यह एक गलत सकारात्मक है तो इस लिस्टिंग को चुनौती दें।