t-mobile[.]njko[.]cc
“Welcome to nginx!”
t-mobile.njko.cc — Konten tidak tersedia (HTTP 502). Ringkasan bukti: VirusTotal 11/93 (Cluster25, CRDF, Emsisoft, Forcepoint ThreatSeeker, Fortinet); URLQuery 2 alerts; PhishDestroy score 87/100. Registrar: Gname.
Analisis terperinci PhishDestroy AI di bawah tetap berbahasa Inggris untuk menjaga catatan forensik asli.
Analysis dated 24 July 2026 shows that t-mobile.njko.cc was registered on 21 February 2026 through Gname.com Pte. Ltd. and points to the Cloudflare‑owned address 188.114.96.3 (AS13335, United States). The domain resolves to a server presenting the default “Welcome to nginx!” page and does not provide an SSL certificate, indicating an unencrypted HTTP service. Nameserver delegation to fiona.ns.cloudflare.com and malcolm.ns.cloudflare.com confirms the use of Cloudflare DNS infrastructure. The site is classified as a brand‑impersonation campaign that purports to mimic x.com, although the page content beyond the generic title has not been captured.
Threat intelligence feeds have listed the domain on one security blocklist and it carries a Gridinsoft trust score of 0 / 100, reflecting extreme distrust. PhishDestroy has already taken the domain offline, and VirusTotal records show that 11 of 93 scanning engines flagged the host as malicious, reinforcing the suspicion of abuse. The combination of a newly created domain, lack of TLS, low trust score, and multiple vendor detections suggests a deliberate attempt to lure victims into credential harvesting or other fraudulent activity against the x.com brand.
Uncertainty remains regarding the exact phishing kit, payload, or victim interaction flow because no further page analysis is available. Defenders should add t-mobile.njko.cc to domain blocklists, monitor for additional sub‑domains under the njko.cc zone, and enforce outbound filtering for HTTP traffic to the IP 188.114.96.3. Continuous re‑scanning with multi‑engine platforms is advised to capture any future changes in the host’s behavior.
Intelijen Keamanan Jaringan
Alur Tanggapan Ancaman Pipeline
Status Daftar Blokir Publik
Analisis VirusTotal
Bukti & Laporan Eksternal
PD-20260203-DA2242 Recipient: complaint@gname.com Apakah Anda Terpengaruh oleh Situs Ini?
Jika Anda memasukkan kredensial akun, informasi pribadi atau pembayaran, atau mengunduh file dari domain ini, segera ambil tindakan. Di bawah ini adalah sumber daya untuk membantu Anda melaporkan insiden tersebut dan melindungi diri Anda sendiri.
Laporkan kepada Pihak Berwenang di Daerah Anda
Pilih negara Anda untuk mendapatkan kontak resmi kejahatan dunia maya, atau membuat draf pengaduan →.
Periksa Domain Apa Pun
Analisis ancaman menggunakan daftar blokir yang disimpan, WHOIS, DNS, dan bukti pemindaian publik
Pindai SekarangLaporkan Phishing
Laporkan domain yang mencurigakan ke basis data ancaman kami — lindungi komunitas
LaporanPemberitahuan Ancaman Real-Time
Laporan phishing terbaru dan perubahan ketersediaan yang diamati
PantauTetap Terinformasi, Tetap Aman
Pantau ancaman secara langsung atau ajukan keberatan terhadap daftar ini jika Anda yakin ini merupakan false positive