t-mobile[.]tedhioi[.]cc
“Welcome to nginx!”
t-mobile.tedhioi.cc — Konten tidak tersedia (HTTP 502). Ringkasan bukti: VirusTotal 14/93 (ADMINUSLabs, Cluster25, CRDF, CyRadar, ESET); URLQuery 2 alerts; Spamhaus DBL_PHISH; PhishDestroy score 95/100. Registrar: Gname.
Analisis terperinci PhishDestroy AI di bawah tetap berbahasa Inggris untuk menjaga catatan forensik asli.
This domain t-mobile.tedhioi.cc was observed resolving to the Cloudflare‑owned address 104.21.91.95 (AS13335, United States). The hosting provider is Cloudflare, as indicated by the nameservers owen.ns.cloudflare.com and rose.ns.cloudflare.com. No TLS certificate is presented; HTTP connections return the default nginx page with the title “Welcome to nginx!”, which suggests the site is either a placeholder or a minimal landing page without legitimate content. The registrar listed for the domain is Gname.com Pte. Ltd., and the registration timestamp is 21 February 2026. The domain is currently marked offline, and the threat has been classified as brand impersonation targeting the brand x.com.
Threat intelligence shows the domain is blocked by PhishDestroy and appears on a single security blocklist. Gridinsoft assigns a trust score of 0 / 100, indicating no perceived legitimacy. On VirusTotal the domain was flagged by 14 of 93 scanning engines, providing independent confirmation of malicious intent. The absence of an SSL certificate further reduces trustworthiness and may facilitate downgrade‑attack vectors.
Analysts should treat t-mobile.tedhioi.cc as a confirmed malicious infrastructure element. Immediate defensive actions include adding the domain and its resolved IP address to network‑level deny lists, updating DNS filtering policies, and ensuring endpoint protection solutions ingest the VirusTotal detection count. Continued monitoring of the associated Cloudflare IP range is advised, as the provider may be reused for other abusive domains. Because the site currently returns only a generic nginx banner, any future content changes cannot be assessed without direct inspection; therefore, periodic re‑resolution and content retrieval are recommended to capture possible escalation.
Intelijen Keamanan Jaringan
Alur Tanggapan Ancaman Pipeline
Status Daftar Blokir Publik
Analisis VirusTotal
Bukti & Laporan Eksternal
PD-20260203-29EA05 Recipient: complaint@gname.com Apakah Anda Terpengaruh oleh Situs Ini?
Jika Anda memasukkan kredensial akun, informasi pribadi atau pembayaran, atau mengunduh file dari domain ini, segera ambil tindakan. Di bawah ini adalah sumber daya untuk membantu Anda melaporkan insiden tersebut dan melindungi diri Anda sendiri.
Laporkan kepada Pihak Berwenang di Daerah Anda
Pilih negara Anda untuk mendapatkan kontak resmi kejahatan dunia maya, atau membuat draf pengaduan →.
Periksa Domain Apa Pun
Analisis ancaman menggunakan daftar blokir yang disimpan, WHOIS, DNS, dan bukti pemindaian publik
Pindai SekarangLaporkan Phishing
Laporkan domain yang mencurigakan ke basis data ancaman kami — lindungi komunitas
LaporanPemberitahuan Ancaman Real-Time
Laporan phishing terbaru dan perubahan ketersediaan yang diamati
PantauTetap Terinformasi, Tetap Aman
Pantau ancaman secara langsung atau ajukan keberatan terhadap daftar ini jika Anda yakin ini merupakan false positive