t-mobile[.]qcuys[.]cc
“Welcome to nginx!”
t-mobile.qcuys.cc — Konten tidak tersedia (HTTP 502). Ringkasan bukti: VirusTotal 12/93 (alphaMountain.ai, Cluster25, CRDF, Emsisoft, Forcepoint ThreatSeeker); URLQuery 4 alerts; PhishDestroy score 86/100. Registrar: Gname.
Analisis terperinci PhishDestroy AI di bawah tetap berbahasa Inggris untuk menjaga catatan forensik asli.
The domain t-mobile.qcuys.cc was observed being used in a brand‑impersonation campaign targeting the x.com brand. Registration data shows the domain was created on 21 February 2026 through Gname.com Pte. Ltd., and it is hosted on Cloudflare’s network (AS13335) with the IP address 188.114.97.3 located in the United States. DNS resolution is served by the Cloudflare authoritative nameservers amalia.ns.cloudflare.com and elliott.ns.cloudflare.com. No TLS certificate is present; HTTP responses return the default nginx page with the title “Welcome to nginx!”. Malware‑scanning services on VirusTotal recorded 12 positive detections out of 93 submitted security vendors, indicating that a subset of scanners flagged the domain as malicious.
Gridinsoft assigned a trust score of 0 / 100, and the domain appears on at least one external blocklist, confirming its inclusion in threat‑sharing feeds. The PhishDestroy blocklist also lists the domain, and it has been taken offline at the time of reporting. Analysis indicates that the infrastructure is typical of low‑cost phishing operations that leverage Cloudflare’s free DNS and CDN services to hide the true origin of the content. The lack of an SSL certificate suggests that the site was not intended for credential collection over encrypted channels, but the presence of multiple vendor detections and a zero trust score point to malicious intent. The exact payload, landing‑page content, and any credential‑harvesting mechanisms have not been captured, leaving the functional details of the impersonation unknown.
Defenders should add the domain, its IP address, and the associated Cloudflare nameservers to network‑level blocking rules. Monitoring for additional domains registered by the same registrar within a similar time window is advisable. Since the site is already offline, incident response teams should still log the indicator of compromise and correlate it with any recent traffic that may have reached the IP before takedown.
Intelijen Keamanan Jaringan
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | t-mobile.qcuys.cc |
malicious | Sinkholed |
| OpenDNS | t-mobile.qcuys.cc |
phishing | Phishing Block |
| Hagezi Threat Feed | t-mobile.qcuys.cc |
malicious | Sinkholed |
| Quad9 DNS | t-mobile.qcuys.cc |
malicious | Sinkholed |
Alur Tanggapan Ancaman Pipeline
Status Daftar Blokir Publik
Analisis VirusTotal
Bukti & Laporan Eksternal
PD-20260124-84F111 Recipient: complaint@gname.com Apakah Anda Terpengaruh oleh Situs Ini?
Jika Anda memasukkan kredensial akun, informasi pribadi atau pembayaran, atau mengunduh file dari domain ini, segera ambil tindakan. Di bawah ini adalah sumber daya untuk membantu Anda melaporkan insiden tersebut dan melindungi diri Anda sendiri.
Laporkan kepada Pihak Berwenang di Daerah Anda
Pilih negara Anda untuk mendapatkan kontak resmi kejahatan dunia maya, atau membuat draf pengaduan →.
Periksa Domain Apa Pun
Analisis ancaman menggunakan daftar blokir yang disimpan, WHOIS, DNS, dan bukti pemindaian publik
Pindai SekarangLaporkan Phishing
Laporkan domain yang mencurigakan ke basis data ancaman kami — lindungi komunitas
LaporanPemberitahuan Ancaman Real-Time
Laporan phishing terbaru dan perubahan ketersediaan yang diamati
PantauTetap Terinformasi, Tetap Aman
Pantau ancaman secara langsung atau ajukan keberatan terhadap daftar ini jika Anda yakin ini merupakan false positive