att[.]kflgt[.]cc
“Welcome to nginx!”
att.kflgt.cc — Conteúdo indisponível. Resumo das evidências: VirusTotal 15/93 (ADMINUSLabs, alphaMountain.ai, BitDefender, Cluster25, CRDF); URLQuery 1 alert; PhishDestroy score 95/100. Registrador: Gname.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
The domain att.kflgt.cc was observed being used in a brand‑impersonation campaign targeting users of x.com. The site resolves to 172.67.177.225, an address owned by Cloudflare, Inc. (AS13335) and hosted in the United States. Both authoritative name servers are Cruz.ns.cloudflare.com and Lex.ns.cloudflare.com, indicating the infrastructure is fully cloud‑flared. No TLS certificate is presented; HTTP requests return the default nginx page with the title “Welcome to nginx!”, suggesting the server is serving a generic placeholder rather than a crafted login portal.
The domain was registered on 21 February 2026 through Gname.com Pte. Ltd., and the Gridinsoft trust score is 0 / 100, reflecting a lack of reputation. VirusTotal analysis shows 15 of 93 vendor scanners flag the domain as malicious, and the domain appears on a single public blocklist that has already been enforced by PhishDestroy, leading to the current offline status. The short lifespan, cloud‑based hosting, and lack of SSL are consistent with a disposable phishing infrastructure. Uncertainty remains around the specific payload delivered to victims because the page content has not been captured; only the default nginx title is available.
Defenders should add att.kflgt.cc to local deny‑lists, monitor DNS queries for the domain and its associated IP, and enforce blocklist rules that include the Cloudflare IP range. Because the registrar is Gname.com, future similar registrations may be tracked through bulk queries of newly created domains from the same registrar. Continuous re‑scanning with sandbox and URL‑reputation services is recommended to detect any re‑activation attempts.
Inteligência de segurança de rede
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | att.kflgt.cc |
malicious | Sinkholed |
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Análise do VirusTotal
Evidências e relatórios externos
PD-20260120-DFD619 Recipient: complaint@gname.com Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo