t-mobile[.]xcues[.]cc
“Welcome to nginx!”
t-mobile.xcues.cc — Contenuto non disponibile (HTTP 502). Riepilogo delle prove: VirusTotal 12/95 (ADMINUSLabs, alphaMountain.ai, Cluster25, CRDF, CyRadar); URLQuery 1 alert; PhishDestroy score 90/100. Registrar: Gname.
L’analisi dettagliata di PhishDestroy AI resta in inglese per preservare il rapporto forense originale.
The domain t-mobile.xcues.cc was registered on 21 February 2026 through Gname.com Pte. Ltd. and currently resolves to the Cloudflare edge address 104.21.60.13, which is advertised as being located in the United States under AS13335 (Cloudflare, Inc.). DNS resolution is served by the authoritative nameservers alla.ns.cloudflare.com and jermaine.ns.cloudflare.com. An HTTP request to the host returns a generic "Welcome to nginx!" page title and no TLS certificate, indicating that the site is operating over plain HTTP only.
Gridinsoft assigned a trust score of 0 out of 100, reflecting a highly malicious assessment. The payload is classified as a brand‑impersonation campaign targeting the x.com brand, and the indicator set includes 12 of 95 VirusTotal scanners flagging the domain as malicious. The domain has been taken offline, but it was previously blocked by PhishDestroy and appears on a single external security blocklist.
Current evidence does not reveal the presence of credential‑stealing forms or additional infrastructure, so the exact phishing kit or payload cannot be confirmed. Defenders should continue to block the domain and its associated IP address at perimeter and DNS layers, monitor for any resurgence of the host under the same IP or similar Cloudflare nameservers, and add the indicator to internal threat‑intel feeds. Ongoing observation of the registrar Gname.com for future registrations that reuse the same naming patterns is also advised.
Informazioni sulla sicurezza di rete
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | t-mobile.xcues.cc |
malicious | Sinkholed |
Pipeline di risposta alle minacce
Stato della lista di blocco pubblica
Analisi di VirusTotal
Dati e relazioni esterne
PD-20260202-08152C Recipient: complaint@gname.com Questo sito ti ha influenzato in qualche modo?
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.
Verifica qualsiasi dominio
Analisi delle minacce utilizzando blocklist archiviate, WHOIS, DNS e prove di scansione pubblica
Scansiona oraSegnala un tentativo di phishing
Segnala i domini sospetti al nostro database delle minacce — proteggi la comunità
SegnalaFeed in tempo reale sulle minacce
Segnalazioni recenti di phishing e modifiche osservate della disponibilità
MonitoraRimani informato, rimani al sicuro
Controlla le minacce in tempo reale oppure contesta questa segnalazione se ritieni che si tratti di un falso positivo