t-mobile[.]qsvij[.]cc
“Welcome to nginx!”
t-mobile.qsvij.cc — Konten tidak tersedia (HTTP 502). Ringkasan bukti: VirusTotal 13 detections (engine total unavailable) (ADMINUSLabs, Chong Lua Dao, Cluster25, CRDF, CyRadar); URLQuery 3 alerts; PhishDestroy score 93/100. Registrar: Gname.
Analisis terperinci PhishDestroy AI di bawah tetap berbahasa Inggris untuk menjaga catatan forensik asli.
Analysis of t-mobile.qsvij.cc indicates a brand impersonation phishing domain targeting x.com, registered on February 21, 2026, through Gname.com Pte. Ltd. The domain resolved to IP 104.21.66.69 (AS13335 Cloudflare, Inc., US) and was served via Cloudflare nameservers marissa.ns.cloudflare.com and olof.ns.cloudflare.com. At the time of assessment, the domain was offline, with no SSL certificate present and an HTTP response displaying the default 'Welcome to nginx!' page title, suggesting either misconfiguration or an incomplete deployment of the phishing infrastructure. Thirteen of 95 security vendors on VirusTotal flagged this domain as malicious, and it appears on at least one security blocklist (PhishDestroy). The Gridinsoft trust score of 0/100 further supports its classification as high-risk.
No evidence links the domain to a specific phishing kit or campaign beyond its stated scam type (brand impersonation). The use of Cloudflare hosting and nameservers is consistent with tactics observed in other phishing operations, where threat actors leverage CDN services to obscure origin servers and evade takedowns. Defenders should treat this domain as confirmed malicious based on detection vendor consensus and blocklist inclusion.
Network-level blocking of 104.21.66.69 and monitoring for related subdomains under qsvij.cc are recommended. Given the domain's offline status, further analysis of its intended payload or victim interaction patterns is not currently possible. Registrar and hosting provider abuse reports have likely contributed to its takedown, but recurrence under similar infrastructure remains a risk.
Intelijen Keamanan Jaringan
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Hagezi Threat Feed | t-mobile.qsvij.cc |
malicious | Sinkholed |
| DNS4EU | t-mobile.qsvij.cc |
malicious | Sinkholed |
| OpenDNS | t-mobile.qsvij.cc |
phishing | Phishing Block |
Alur Tanggapan Ancaman Pipeline
Status Daftar Blokir Publik
Analisis VirusTotal
Bukti & Laporan Eksternal
PD-20260202-C62299 Recipient: complaint@gname.com Apakah Anda Terpengaruh oleh Situs Ini?
Jika Anda memasukkan kredensial akun, informasi pribadi atau pembayaran, atau mengunduh file dari domain ini, segera ambil tindakan. Di bawah ini adalah sumber daya untuk membantu Anda melaporkan insiden tersebut dan melindungi diri Anda sendiri.
Laporkan kepada Pihak Berwenang di Daerah Anda
Pilih negara Anda untuk mendapatkan kontak resmi kejahatan dunia maya, atau membuat draf pengaduan →.
Periksa Domain Apa Pun
Analisis ancaman menggunakan daftar blokir yang disimpan, WHOIS, DNS, dan bukti pemindaian publik
Pindai SekarangLaporkan Phishing
Laporkan domain yang mencurigakan ke basis data ancaman kami — lindungi komunitas
LaporanPemberitahuan Ancaman Real-Time
Laporan phishing terbaru dan perubahan ketersediaan yang diamati
PantauTetap Terinformasi, Tetap Aman
Pantau ancaman secara langsung atau ajukan keberatan terhadap daftar ini jika Anda yakin ini merupakan false positive