t-mobile[.]virnokw[.]cc
“Welcome to nginx!”
t-mobile.virnokw.cc — Konten tidak tersedia (HTTP 502). Ringkasan bukti: VirusTotal 13/93 (ADMINUSLabs, Cluster25, CRDF, Emsisoft, Forcepoint ThreatSeeker); URLQuery 2 alerts; PhishDestroy score 93/100. Registrar: Gname.
Analisis terperinci PhishDestroy AI di bawah tetap berbahasa Inggris untuk menjaga catatan forensik asli.
The domain t-mobile.virnokw.cc was registered on 21 February 2026 via the registrar Gname.com Pte. Ltd. and is presently marked as offline. Authoritative name servers resolve to priscilla.ns.cloudflare.com and yisroel.ns.cloudflare.com, confirming that the domain is hosted behind Cloudflare’s network (ASN 13335, United States). DNS resolution returns the IP address 172.67.208.32, which belongs to Cloudflare’s edge infrastructure. No TLS certificate is presented for the host, and an HTTP request returns the default page title “Welcome to nginx!”, indicating that the web server is responding with a generic Nginx landing page rather than a brand‑specific interface.
Threat intelligence flags the domain as a brand‑impersonation campaign targeting the brand x.com. VirusTotal reports that 13 of 93 scanning engines have flagged the domain as malicious, and the domain appears on a single external blocklist. Additional corroboration comes from PhishDestroy, which has already blocked the host. The Gridinsoft trust score of 0 / 100 reinforces the low confidence in the site’s legitimacy.
Because the site is offline, active content cannot be inspected, and the exact phishing payload, credential‑capture mechanisms, or redirection chains remain unknown. Absence of a TLS certificate and the presence of only a default Nginx page suggest that the domain may have been used transiently to host malicious content before being taken down. Defenders should add t-mobile.virnokw.cc to URL filtering and host‑based deny lists, monitor the associated Cloudflare IP (172.67.208.32) for any re‑use, and enforce strict TLS inspection policies to detect future attempts to serve phishing pages without valid certificates. Continuous re‑scanning with multi‑engine services is advised to capture any changes should the domain be re‑activated.
Intelijen Keamanan Jaringan
Alur Tanggapan Ancaman Pipeline
Status Daftar Blokir Publik
Analisis VirusTotal
Bukti & Laporan Eksternal
PD-20260203-B125FE Recipient: complaint@gname.com Apakah Anda Terpengaruh oleh Situs Ini?
Jika Anda memasukkan kredensial akun, informasi pribadi atau pembayaran, atau mengunduh file dari domain ini, segera ambil tindakan. Di bawah ini adalah sumber daya untuk membantu Anda melaporkan insiden tersebut dan melindungi diri Anda sendiri.
Laporkan kepada Pihak Berwenang di Daerah Anda
Pilih negara Anda untuk mendapatkan kontak resmi kejahatan dunia maya, atau membuat draf pengaduan →.
Periksa Domain Apa Pun
Analisis ancaman menggunakan daftar blokir yang disimpan, WHOIS, DNS, dan bukti pemindaian publik
Pindai SekarangLaporkan Phishing
Laporkan domain yang mencurigakan ke basis data ancaman kami — lindungi komunitas
LaporanPemberitahuan Ancaman Real-Time
Laporan phishing terbaru dan perubahan ketersediaan yang diamati
PantauTetap Terinformasi, Tetap Aman
Pantau ancaman secara langsung atau ajukan keberatan terhadap daftar ini jika Anda yakin ini merupakan false positive