t-mobile[.]qwopt[.]cc
“Welcome to nginx!”
Riepilogo delle prove
This domain, t-mobile.qwopt.cc, is flagged as a brand impersonation phishing site targeting X.com users. Analysis indicates the infrastructure was configured to harvest login credentials, likely through a spoofed authentication portal. The page title 'Welcome to nginx!' suggests a default server configuration, possibly indicative of hastily deployed or repurposed phishing infrastructure. No drainer kit signatures were identified in the available telemetry, though the lack of SSL encryption and default server banner increase the likelihood of credential interception. Technical indicators confirm elevated risk: the domain was registered on February 21, 2026, through Dominet (HK) Limited, and resolves to IP 47.253.81.117, hosted on Alibaba (US) Technology Co., Ltd. infrastructure (AS45102). VirusTotal detection stands at 20/95 security vendors, while the domain appears on one security blocklist. No Google Safe Browsing (GSB) entries were recorded prior to takedown. The absence of an SSL certificate further undermines secure communication, aligning with common phishing tactics to avoid encryption-related warnings. The domain is currently offline, having been taken down following detection. Response actions included blocking by security providers and removal from DNS resolution. Despite its inactive status, residual risk persists due to potential reuse of the IP or registration of similar domains under the same registrar. Users who may have interacted with the site are advised to rotate credentials immediately and monitor for unauthorized account activity. Organizations should review logs for connections to 47.253.81.117 and assess exposure to brand impersonation campaigns targeting social media platforms.
Istantanea delle prove inviate
- Inviato
- Voci del registro
- 1
- ID del caso
PD-20260130-435F7E- Titolo della pagina acquisita
- Welcome to nginx!
- Artefatto PDF
- Prova in PDF
Base giuridica
Testo completo delle prove
Section 3.1 of the AUP: The domain t-mobile.qwopt.cc is engaged in phishing activities, specifically impersonating a well-known telecommunications company to deceive users into providing sensitive personal information.
Section 4.2 of the TOS: The registrar reserves the right to suspend services for any activities that violate laws or regulations. The operation of this phishing domain constitutes a clear violation of this provision.
Applicable Laws (Unknown):
Computer Fraud and Abuse Act (CFAA): This U.S. law prohibits unauthorized access to computers and the fraudulent use of such access, which is applicable to phishing schemes.
Wire Fraud Statute (18 U.S.C. § 1343): This law criminalizes schemes to defraud individuals or entities through electronic communications, which is directly relevant to the activities conducted by this domain.
Anti-Phishing Consumer Protection Act: This legislation aims to combat phishing and other deceptive online practices, making it illegal to engage in such activities.
Regulatory Note: Failure to act on this report may expose your organization to legal liability and regulatory scrutiny. Immediate action is recommended to mitigate potential risks associated with non-compliance.
Data Coverage
Informazioni sulla sicurezza di rete
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | t-mobile.qwopt.cc |
malicious | Sinkholed |
| Cloudflare DNS | t-mobile.qwopt.cc |
malicious | Sinkholed |
| OpenDNS | t-mobile.qwopt.cc |
phishing | Phishing Block |
| Quad9 DNS | t-mobile.qwopt.cc |
malicious | Sinkholed |
| Hagezi Threat Feed | t-mobile.qwopt.cc |
malicious | Sinkholed |
Pipeline di risposta alle minacce
Copertura delle blocklist
10 fonti esterne monitorate · snapshot del 13/08/2026
10 fonti esterne monitorate Nessuna corrispondenza
Cronologia del rilevamento
-
Cloudflare Radar
Scansione Cloudflare Radar archiviata · Apri scansione
Analisi di VirusTotal
Questo sito ti ha influenzato in qualche modo?
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.
Verifica qualsiasi dominio
Analisi delle minacce utilizzando blocklist archiviate, WHOIS, DNS e prove di scansione pubblica
Scansiona oraSegnala un tentativo di phishing
Segnala i domini sospetti al nostro database delle minacce — proteggi la comunità
SegnalaFeed in tempo reale sulle minacce
Segnalazioni recenti di phishing e modifiche osservate della disponibilità
MonitoraRimani informato, rimani al sicuro
Controlla le minacce in tempo reale oppure contesta questa segnalazione se ritieni che si tratti di un falso positivo