t-mobile[.]qaxvb[.]cc
“Welcome to nginx!”
t-mobile.qaxvb.cc — Konten tidak tersedia (HTTP 502). Ringkasan bukti: VirusTotal 18/93 (ADMINUSLabs, Criminal IP, BitDefender, Cluster25, CRDF); Spamhaus DBL_PHISH; PhishDestroy score 95/100. Registrar: Dominet (HK).
Analisis terperinci PhishDestroy AI di bawah tetap berbahasa Inggris untuk menjaga catatan forensik asli.
This domain is flagged for elevated-risk brand impersonation, specifically targeting x.com through deceptive infrastructure. Analysis indicates the site was designed to mimic legitimate login portals, likely to harvest credentials or distribute malicious payloads under the guise of a trusted platform. The threat type aligns with targeted phishing campaigns exploiting brand recognition to bypass user vigilance. Infrastructure analysis reveals the domain was registered on February 21, 2026, through Dominet (HK) Limited, a registrar frequently associated with high-risk domains. It resolves to IP 8.219.239.111, hosted on Alibaba (US) Technology Co., Ltd. infrastructure (AS45102) in Singapore. Security vendor detections on VirusTotal reached 18/95, with the domain appearing on at least one security blocklist. The absence of an SSL certificate and the default nginx welcome page suggest either an incomplete deployment or a placeholder for future malicious activity. No historical content was captured prior to takedown, limiting forensic reconstruction. Mitigation steps for this threat type include blocking the domain and its resolving IP at network perimeter controls. Organizations should monitor for credential reuse attempts from harvested accounts, particularly those associated with x.com. Endpoint detection rules should prioritize alerts for connections to newly registered domains under offshore registrars, especially those mimicking high-value brands. Security teams are advised to correlate this domain with other indicators from the same registrar or hosting provider to identify potential campaign clusters. User awareness training should emphasize verification of domain authenticity before entering credentials, even when pages appear visually legitimate.
Alur Tanggapan Ancaman Pipeline
Status Daftar Blokir Publik
Analisis VirusTotal
Bukti & Laporan Eksternal
PD-20260122-2693E8 Recipient: domainabuse@service.aliyun.com Apakah Anda Terpengaruh oleh Situs Ini?
Jika Anda memasukkan kredensial akun, informasi pribadi atau pembayaran, atau mengunduh file dari domain ini, segera ambil tindakan. Di bawah ini adalah sumber daya untuk membantu Anda melaporkan insiden tersebut dan melindungi diri Anda sendiri.
Laporkan kepada Pihak Berwenang di Daerah Anda
Pilih negara Anda untuk mendapatkan kontak resmi kejahatan dunia maya, atau membuat draf pengaduan →.
Periksa Domain Apa Pun
Analisis ancaman menggunakan daftar blokir yang disimpan, WHOIS, DNS, dan bukti pemindaian publik
Pindai SekarangLaporkan Phishing
Laporkan domain yang mencurigakan ke basis data ancaman kami — lindungi komunitas
LaporanPemberitahuan Ancaman Real-Time
Laporan phishing terbaru dan perubahan ketersediaan yang diamati
PantauTetap Terinformasi, Tetap Aman
Pantau ancaman secara langsung atau ajukan keberatan terhadap daftar ini jika Anda yakin ini merupakan false positive