att[.]jxdin[.]cc
“Holiday Deals 2025 | AT&T”
Riepilogo delle prove
The domain att.jxdin.cc was registered on 26 January 2026 through Gname.com Pte. Ltd. and is hosted on the Cloudflare network (AS13335) with the address 172.67.179.220, a US‑based edge node. DNS resolution is provided by the authoritative pair A.SHARE-DNS.COM and B.SHARE-DNS.NET. The site presented a page titled “Holiday Deals 2025 | AT&T”, yet the intelligence tags the operation as a “Tech Support Scam” that impersonates Apple. The SSL certificate listed as WE1 is valid for the host, indicating that TLS termination is performed by Cloudflare rather than the malicious operator. Reputation metrics are extremely low: Gridinsoft assigns a score of 0 / 100 and Scamadviser a score of 1 / 100.
The domain appears on a single public blocklist and is actively blocked by PhishDestroy. VirusTotal analysis shows that 16 out of 93 scanning engines flagged the domain, reinforcing the malicious assessment. No additional public safe‑browsing or OTX entries are present in the supplied data. The current operational status is offline, which limits immediate observation of payloads or redirects, but the combination of a brand‑impersonating page title, low trust scores, blocklist presence, and multiple vendor detections indicates a high likelihood of credential‑harvesting or remote‑access social engineering.
Uncertainties remain regarding the exact content served before takedown and whether any C2 infrastructure was leveraged. Defenders should add att.jxdin.cc to internal block or deny lists, monitor for any residual traffic to the Cloudflare IP, and enforce strict email and web filtering for Apple‑related phishing attempts. Continuous observation of the associated IP range and the hosting provider’s abuse channels is advised, as the attacker may shift to new domains using the same infrastructure. Incident response teams should also verify that any user‑reported contacts claiming Apple support are correlated with this domain to facilitate rapid containment.
Data Coverage
Pipeline di risposta alle minacce
Copertura delle blocklist
10 fonti esterne monitorate · snapshot del 12/08/2026
10 fonti esterne monitorate Nessuna corrispondenza
Informazioni forensi
Analisi di VirusTotal
Questo sito ti ha influenzato in qualche modo?
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.
Verifica qualsiasi dominio
Analisi delle minacce utilizzando blocklist archiviate, WHOIS, DNS e prove di scansione pubblica
Scansiona oraSegnala un tentativo di phishing
Segnala i domini sospetti al nostro database delle minacce — proteggi la comunità
SegnalaFeed in tempo reale sulle minacce
Segnalazioni recenti di phishing e modifiche osservate della disponibilità
MonitoraRimani informato, rimani al sicuro
Controlla le minacce in tempo reale oppure contesta questa segnalazione se ritieni che si tratti di un falso positivo