att[.]qhosm[.]cc
“Welcome to nginx!”
att.qhosm.cc — Konten tidak tersedia. Ringkasan bukti: VirusTotal 11/93 (Cluster25, CRDF, Emsisoft, Forcepoint ThreatSeeker, Fortinet); Spamhaus DBL_PHISH; PhishDestroy score 83/100. Registrar: Gname.
Analisis terperinci PhishDestroy AI di bawah tetap berbahasa Inggris untuk menjaga catatan forensik asli.
Analysis of the domain att.qhosm.cc indicates a confirmed brand impersonation phishing campaign targeting X.com, with elevated risk classification. The domain was registered on February 21, 2026, through Gname.com Pte. Ltd., a registrar frequently associated with abusive registrations. Infrastructure analysis reveals the domain resolves to IP address 104.21.91.238, hosted on Cloudflare's network (AS13335) in the United States. Nameservers marek.ns.cloudflare.com and savanna.ns.cloudflare.com further confirm Cloudflare as the DNS provider. At the time of assessment, the domain is offline, though prior HTTP responses returned the default page title 'Welcome to nginx!', suggesting misconfigured or placeholder server deployment rather than a fully operational phishing page.
Detection data from July 24, 2026, shows 11 of 93 security vendors on VirusTotal flagging att.qhosm.cc as malicious, while PhishDestroy has explicitly blocked the domain. The domain appears on one additional security blocklist, reinforcing its classification as a phishing threat. No SSL certificate is present, increasing the likelihood of interception or distrust by modern browsers. Gridinsoft's trust score of 0/100 further corroborates the domain's malicious intent, though the absence of additional context—such as phishing kit artifacts or redirect chains—limits deeper attribution. Defenders should treat this domain as a confirmed phishing resource targeting X.com users.
While the domain is currently offline, its infrastructure remains intact, and reactivation is possible. Network-level blocking of 104.21.91.238 and monitoring for related domains registered via Gname.com Pte. Ltd. are recommended. The lack of SSL and the use of Cloudflare infrastructure suggest the campaign may have been in an early or transitional phase at the time of takedown. Further analysis of historical DNS records or passive DNS data could reveal additional related domains or IP associations.
Alur Tanggapan Ancaman Pipeline
Status Daftar Blokir Publik
Analisis VirusTotal
Bukti & Laporan Eksternal
PD-20260203-6582B7 Recipient: complaint@gname.com Apakah Anda Terpengaruh oleh Situs Ini?
Jika Anda memasukkan kredensial akun, informasi pribadi atau pembayaran, atau mengunduh file dari domain ini, segera ambil tindakan. Di bawah ini adalah sumber daya untuk membantu Anda melaporkan insiden tersebut dan melindungi diri Anda sendiri.
Laporkan kepada Pihak Berwenang di Daerah Anda
Pilih negara Anda untuk mendapatkan kontak resmi kejahatan dunia maya, atau membuat draf pengaduan →.
Periksa Domain Apa Pun
Analisis ancaman menggunakan daftar blokir yang disimpan, WHOIS, DNS, dan bukti pemindaian publik
Pindai SekarangLaporkan Phishing
Laporkan domain yang mencurigakan ke basis data ancaman kami — lindungi komunitas
LaporanPemberitahuan Ancaman Real-Time
Laporan phishing terbaru dan perubahan ketersediaan yang diamati
PantauTetap Terinformasi, Tetap Aman
Pantau ancaman secara langsung atau ajukan keberatan terhadap daftar ini jika Anda yakin ini merupakan false positive