t-mobile[.]fenrd[.]cc
“Welcome to nginx!”
証拠の概要
Analysis of the domain t-mobile.fenrd.cc indicates it was actively involved in brand impersonation targeting X.com, as documented in threat intelligence records from July 2026. The domain, registered on February 21, 2026, through Gname.com Pte. Ltd., resolved to the IP address 104.21.31.62, which is hosted on Cloudflare's infrastructure (AS13335) in the United States. At the time of assessment, the domain was offline, with no SSL certificate detected and an HTTP response displaying the default 'Welcome to nginx!' page title, suggesting either misconfiguration or an incomplete deployment of phishing infrastructure. Detection metrics reveal limited but clear indicators of malicious activity. The domain appeared on one security blocklist and was flagged by PhishDestroy.
VirusTotal records show that 17 out of 95 security vendors classified the domain as malicious, though the specific nature of the detections—whether related to phishing, malware, or other abuse—remains unconfirmed. The Gridinsoft trust score of 0/100 further corroborates its high-risk classification. Nameservers carlane.ns.cloudflare.com and trey.ns.cloudflare.com, also operated by Cloudflare, were associated with the domain, a common pattern in phishing campaigns leveraging Cloudflare's proxy services to obscure origin servers. The scam type is explicitly categorized as brand impersonation, with X.com identified as the targeted brand. While the domain is no longer active, its infrastructure and detection history align with known phishing tactics.
Defenders are advised to monitor for residual DNS records, subdomains, or related infrastructure that may resurface under different names. Organizations should update blocklists to include this domain and investigate any prior connections from internal networks. Given the use of Cloudflare, additional scrutiny of domains sharing the same nameservers or IP ranges may uncover related malicious activity.
送信済み証拠のスナップショット
- 送信日時
- 台帳レコード
- 1
- ケース ID
PD-20260118-EFCA9C- 取得ページのタイトル
- Welcome to nginx!
- PDF 資料
- 証拠 PDF
証拠全文
Policy Violations: Illegal Activities section forbids phishing, fraud, fake sites, malware distribution; registrar investigates and may suspend or delete domain
Applicable Laws: Computer Misuse Act 1993 §§3+, Penal Code §§415–420 (cheating), Online Criminal Harms Act (OCHA)
Data Coverage
ネットワークセキュリティインテリジェンス
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| OpenDNS | t-mobile.fenrd.cc |
phishing | Phishing Block |
| Hagezi Threat Feed | t-mobile.fenrd.cc |
malicious | Sinkholed |
脅威対応 Pipeline
ブロックリストの確認範囲
監視対象の外部情報源 10 件 · 保存スナップショット 2026年8月13日
検出タイムライン
-
Cloudflare Radar
Cloudflare Radar スキャンを保存 · スキャンを開く
VirusTotalによる分析
このサイトによって何か影響を受けましたか?
アカウント資格情報、個人情報、支払い情報を入力した場合、またはこのドメインからファイルをダウンロードした場合は、すぐに対処してください。インシデントを報告し、自分自身を守るのに役立つリソースを以下に示します。
お住まいの地域の当局へ報告してください
サイバー犯罪の公式連絡先 または 苦情草稿を作成する → を取得するには、国を選択してください。
任意のドメインを確認する
保存されたブロックリスト、WHOIS、DNS、および公開スキャン証拠を使用した脅威分析
今すぐスキャンフィッシングを報告する
不審なドメインを当社の脅威データベースに報告してください — コミュニティを守りましょう
レポートリアルタイム脅威情報フィード
最近のフィッシングレポートと観察された可用性の変化
監視最新情報を入手し、安全を確保しましょう
リアルタイムの脅威を監視するか、誤検知だと思われる場合はこのリストに異議を申し立ててください