att[.]afrxe[.]cc
“Welcome to nginx!”
Ringkasan bukti
Analysis of the domain att.afrxe.cc, observed on July 23, 2026, indicates an active brand‑impersonation campaign aimed at users of x.com. The domain was registered on February 21 2026 through Gname.com Pte. Ltd. and is hosted on Cloudflare infrastructure (AS13335), resolving to the IP address 188.114.96.3 located in the United States. DNS resolution points to the Cloudflare nameservers marek.ns.cloudflare.com and savanna.ns.cloudflare.com. No TLS certificate is presented; HTTP requests return the default “Welcome to nginx!” page title, suggesting the server is serving an unconfigured nginx instance rather than a crafted login portal.
Threat intelligence aggregators have flagged the domain: VirusTotal reports 16 of 95 security vendors as positive, Gridinsoft assigns a trust score of 0 / 100, and the domain appears on a single external blocklist. The phishing‑defense service PhishDestroy has already taken the domain offline and marks it as blocked. The current status is listed as offline, indicating that the malicious site is no longer reachable at the time of analysis. The available evidence confirms the use of the domain for brand impersonation, but the specific content served, credential‑stealing mechanisms, or any associated malware payload remain unknown because the site returns only a generic nginx banner.
Consequently, defenders cannot attribute additional indicators such as malicious URLs, scripts, or phishing emails to the domain at this stage. Recommendations: security teams should continue to block att.afrxe.cc at network perimeter and DNS layers, monitor for any resurgence of the domain or similar sub‑domains hosted on the same IP range, and incorporate the observed indicators (registration date, registrar, IP address, and nameservers) into threat‑intel feeds. Incident response personnel should also check recent email traffic for references to x.
Snapshot bukti yang dikirim
- Dikirim
- Catatan buku besar
- 1
- ID kasus
PD-20260203-BD93EB- Judul halaman yang direkam
- Welcome to nginx!
- Artefak PDF
- Bukti PDF
Teks bukti lengkap
Policy Violations: Illegal Activities section forbids phishing, fraud, fake sites, malware distribution; registrar investigates and may suspend or delete domain
Applicable Laws: Computer Misuse Act 1993 §§3+, Penal Code §§415–420 (cheating), Online Criminal Harms Act (OCHA)
Data Coverage
Alur Tanggapan Ancaman Pipeline
Cakupan daftar blokir
10 sumber eksternal dipantau · snapshot tersimpan 12/08/2026
Linimasa deteksi
-
Cloudflare Radar
Pemindaian Cloudflare Radar tersimpan · Buka pemindaian
Laporan komunitas
Dilaporkan oleh 1 anggota komunitas; pertama terlihat 03/02/2026
- Laporan tersimpan
- 1
- URL unik yang dilaporkan
- 1
Analisis VirusTotal
Apakah Anda Terpengaruh oleh Situs Ini?
Jika Anda memasukkan kredensial akun, informasi pribadi atau pembayaran, atau mengunduh file dari domain ini, segera ambil tindakan. Di bawah ini adalah sumber daya untuk membantu Anda melaporkan insiden tersebut dan melindungi diri Anda sendiri.
Laporkan kepada Pihak Berwenang di Daerah Anda
Pilih negara Anda untuk mendapatkan kontak resmi kejahatan dunia maya, atau membuat draf pengaduan →.
Periksa Domain Apa Pun
Analisis ancaman menggunakan daftar blokir yang disimpan, WHOIS, DNS, dan bukti pemindaian publik
Pindai SekarangLaporkan Phishing
Laporkan domain yang mencurigakan ke basis data ancaman kami — lindungi komunitas
LaporanPemberitahuan Ancaman Real-Time
Laporan phishing terbaru dan perubahan ketersediaan yang diamati
PantauTetap Terinformasi, Tetap Aman
Pantau ancaman secara langsung atau ajukan keberatan terhadap daftar ini jika Anda yakin ini merupakan false positive