t-mobile[.]virnoto[.]cc
“Welcome to nginx!”
t-mobile.virnoto.cc — コンテンツが利用できません (HTTP 502). 証拠の概要: VirusTotal 13/93 (ADMINUSLabs, Cluster25, CRDF, CyRadar, ESET); URLQuery 2 alerts; PhishDestroy score 93/100. レジストラ: Gname.
元のフォレンジック記録を保持するため、下の PhishDestroy AI 詳細分析は英語のままです。
This domain, t-mobile.virnoto.cc, was observed being used in a brand‑impersonation campaign that targets the x.com brand. The domain was registered on 21 February 2026 through Gname.com Pte. Ltd. and is hosted on Cloudflare infrastructure (AS13335) with the IP address 104.21.9.254 located in the United States. DNS resolution points to Cloudflare name servers priscilla.ns.cloudflare.com and yisroel.ns.cloudflare.com, a configuration commonly used by malicious actors to leverage the provider’s global network and hide the true origin of the payload. The web server responds with the generic title “Welcome to nginx!” and does not present an SSL certificate, indicating that the site is served over plain HTTP. At the time of analysis the host was taken offline, but historical data show that the domain appeared on a single security blocklist and was actively blocked by the PhishDestroy feed.
VirusTotal records indicate that 13 of 93 scanning engines flagged the domain, reinforcing the suspicion of malicious use. The Gridinsoft trust score of 0 / 100 further corroborates the lack of legitimacy. Evidence confirms the domain’s primary intent is to impersonate x.com, although the exact page content and phishing kit have not been disclosed. No additional public threat‑intel sources such as OTX entries or Google Safe Browsing reports are linked to this indicator. The absence of an SSL certificate and the use of a default nginx page suggest a minimalistic deployment, likely intended solely to host a redirect or credential‑harvesting endpoint.
Defenders should add t-mobile.virnoto.cc to internal blocklists and monitor DNS queries for the associated Cloudflare name servers. Because the domain resolves to a shared Cloudflare IP, network‑level filtering based on the IP alone may generate false positives; therefore, rule sets should target the fully qualified domain name.
ネットワークセキュリティインテリジェンス
脅威対応 Pipeline
公開ブロックリスト登録状況
VirusTotalによる分析
証拠および外部報告書
PD-20260203-729CD4 Recipient: complaint@gname.com このサイトによって何か影響を受けましたか?
アカウント資格情報、個人情報、支払い情報を入力した場合、またはこのドメインからファイルをダウンロードした場合は、すぐに対処してください。インシデントを報告し、自分自身を守るのに役立つリソースを以下に示します。
お住まいの地域の当局へ報告してください
サイバー犯罪の公式連絡先 または 苦情草稿を作成する → を取得するには、国を選択してください。
任意のドメインを確認する
保存されたブロックリスト、WHOIS、DNS、および公開スキャン証拠を使用した脅威分析
今すぐスキャンフィッシングを報告する
不審なドメインを当社の脅威データベースに報告してください — コミュニティを守りましょう
レポートリアルタイム脅威情報フィード
最近のフィッシングレポートと観察された可用性の変化
監視最新情報を入手し、安全を確保しましょう
リアルタイムの脅威を監視するか、誤検知だと思われる場合はこのリストに異議を申し立ててください