t-mobile[.]tvgha[.]cc
“Welcome to nginx!”
t-mobile.tvgha.cc — Contenuto non disponibile (HTTP 502). Riepilogo delle prove: VirusTotal 20/95 (ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, Cluster25); URLQuery 1 alert; PhishDestroy score 95/100. Registrar: Gname.
L’analisi dettagliata di PhishDestroy AI resta in inglese per preservare il rapporto forense originale.
This domain, t-mobile.tvgha.cc, is identified as a brand impersonation threat designed to mimic X.com, formerly Twitter. The site likely presented a counterfeit login portal to harvest user credentials, session tokens, or other sensitive authentication details. Brand impersonation pages often employ visual mimicry—such as cloned logos, color schemes, and interface layouts—to deceive visitors into believing they are interacting with a legitimate service. In this case, the domain name itself attempts to exploit trust in the T-Mobile brand while redirecting users to a fraudulent X.com login interface, increasing the likelihood of successful credential theft. Analysis indicates the domain was registered on February 21, 2026, through Gname.com Pte. Ltd., a registrar frequently associated with high-risk domains. The site resolved to the IP address 104.21.13.125, hosted on Cloudflare’s network (AS13335), which is commonly used to mask the true origin of malicious infrastructure. At the time of assessment, the domain displayed the default page title “Welcome to nginx!,” suggesting either an incomplete deployment or an attempt to evade detection by presenting minimal content. VirusTotal reports 20 out of 95 security vendors flagging the domain as malicious, while it appears on one security blocklist. The absence of an SSL certificate further undermines any semblance of legitimacy, as modern web services universally enforce HTTPS for secure communication. If you visited t-mobile.tvgha.cc or entered any login credentials, immediate action is required. First, revoke access to any active sessions on X.com by visiting the platform’s security settings and logging out of all devices. Reset your X.com password using a strong, unique passphrase, and enable multi-factor authentication if not already active. Monitor your account for unauthorized activity, including posts, direct messages, or linked applications you did not authorize. If financial information or payment methods were exposed, contact your bank or card issuer to report potential fraud. Finally, scan your device for malware using updated security tools, as some phishing pages may attempt to deliver secondary payloads. Avoid reusing passwords across services, and verify the authenticity of any domain before entering credentials.
Informazioni sulla sicurezza di rete
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | t-mobile.tvgha.cc |
malicious | Sinkholed |
Pipeline di risposta alle minacce
Stato della lista di blocco pubblica
Analisi di VirusTotal
Dati e relazioni esterne
PD-20260203-FB4EC7 Recipient: complaint@gname.com Questo sito ti ha influenzato in qualche modo?
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.
Verifica qualsiasi dominio
Analisi delle minacce utilizzando blocklist archiviate, WHOIS, DNS e prove di scansione pubblica
Scansiona oraSegnala un tentativo di phishing
Segnala i domini sospetti al nostro database delle minacce — proteggi la comunità
SegnalaFeed in tempo reale sulle minacce
Segnalazioni recenti di phishing e modifiche osservate della disponibilità
MonitoraRimani informato, rimani al sicuro
Controlla le minacce in tempo reale oppure contesta questa segnalazione se ritieni che si tratti di un falso positivo