t-mobile[.]codngitd[.]cc
“Welcome to nginx!”
Ringkasan bukti
Analysis of t-mobile.codngitd.cc, registered on February 21 2026 through Gname.com Pte. Ltd., shows infrastructure consistent with a brand‑impersonation campaign targeting x.com. The domain resolves to 104.21.5.47, an address announced by AS13335 Cloudflare, Inc. and geolocated to the United States. Both celeste.ns.cloudflare.com and mike.ns.cloudflare.com serve as authoritative name servers, indicating the use of Cloudflare DNS. The web server returns the generic title “Welcome to nginx!” and presents no TLS certificate, leaving the connection unencrypted. A Gridinsoft trust score of 0 / 100 further reflects a malicious classification.
The domain appears on one external blocklist and has been explicitly blocked by PhishDestroy. VirusTotal reports 13 of 93 scanning engines flagging the host, confirming detection by multiple security vendors. The elevated risk rating aligns with the observed detection profile, and the impersonation of x.com confirms the brand‑impersonation intent. Absence of a valid SSL certificate eliminates any claim of legitimacy and matches the observed “Welcome to nginx!” response, a default page often used by temporary hosting. The presence of Cloudflare’s CDN suggests the operator may rely on its performance and anonymity features.
Although the site is offline at the time of reporting, the persistent DNS records and the IP address remain resolvable, allowing threat actors to reactivate the domain quickly. Security teams should add the domain and its resolving IP to network‑level blocklists, monitor DNS queries for the associated Cloudflare name servers, and enforce HTTPS‑only policies to mitigate accidental exposure. Defenders should incorporate the domain’s IP‑address pair into indicator‑of‑compromise feeds and correlate any inbound traffic targeting x.com credentials. Given the moderate blocklist presence, additional monitoring through threat‑intel platforms can reveal re‑emergence or related infrastructure.
Snapshot bukti yang dikirim
- Dikirim
- Catatan buku besar
- 1
- ID kasus
PD-20260203-39B86F
Teks bukti lengkap
Policy Violations: Illegal Activities section forbids phishing, fraud, fake sites, malware distribution; registrar investigates and may suspend or delete domain
Applicable Laws: Computer Misuse Act 1993 §§3+, Penal Code §§415–420 (cheating), Online Criminal Harms Act (OCHA)
Data Coverage
Intelijen Keamanan Jaringan
Alur Tanggapan Ancaman Pipeline
Cakupan daftar blokir
10 sumber eksternal dipantau · snapshot tersimpan 10/08/2026
Linimasa deteksi
-
Cloudflare Radar
Pemindaian Cloudflare Radar tersimpan · Buka pemindaian
Analisis VirusTotal
Apakah Anda Terpengaruh oleh Situs Ini?
Jika Anda memasukkan kredensial akun, informasi pribadi atau pembayaran, atau mengunduh file dari domain ini, segera ambil tindakan. Di bawah ini adalah sumber daya untuk membantu Anda melaporkan insiden tersebut dan melindungi diri Anda sendiri.
Laporkan kepada Pihak Berwenang di Daerah Anda
Pilih negara Anda untuk mendapatkan kontak resmi kejahatan dunia maya, atau membuat draf pengaduan →.
Periksa Domain Apa Pun
Analisis ancaman menggunakan daftar blokir yang disimpan, WHOIS, DNS, dan bukti pemindaian publik
Pindai SekarangLaporkan Phishing
Laporkan domain yang mencurigakan ke basis data ancaman kami — lindungi komunitas
LaporanPemberitahuan Ancaman Real-Time
Laporan phishing terbaru dan perubahan ketersediaan yang diamati
PantauTetap Terinformasi, Tetap Aman
Pantau ancaman secara langsung atau ajukan keberatan terhadap daftar ini jika Anda yakin ini merupakan false positive