t-mobile[.]vthuw[.]cc
“Welcome to nginx!”
t-mobile.vthuw.cc — Conteúdo indisponível (HTTP 502). Resumo das evidências: VirusTotal 13/93 (ADMINUSLabs, Cluster25, CRDF, CyRadar, Forcepoint ThreatSeeker); Spamhaus DBL_PHISH; PhishDestroy score 89/100.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
The domain t-mobile.vthuw.cc was registered on February 21, 2026 and is currently taken offline. It is listed as a brand impersonation campaign targeting x.com. Infrastructure analysis shows the domain resolves to IP address 172.67.176.58, which belongs to AS13335 Cloudflare, Inc. and is geolocated in the United States. The site presented the default nginx page title "Welcome to nginx!" and used an SSL certificate identified as WE1, suggesting a generic or self‑signed certificate rather than a brand‑validated chain.
Reputation services scored the domain at zero out of one hundred on both Scamadviser and Gridinsoft, indicating a lack of trust. The domain was blocked by the PhishDestroy blocklist and appears on one additional security blocklist. VirusTotal recorded 13 detections out of 93 scanned security vendors, confirming that multiple scanners flagged the host as malicious.
No further content analysis is available because the site is offline, leaving the exact phishing payload or login collection mechanisms unverified. Defenders should immediately add t-mobile.vthuw.cc to network deny lists, monitor for any future resolution to the same Cloudflare IP range, and enforce email and web filtering policies that detect brand impersonation attempts referencing x.com. Continuous threat‑intel feeds should be consulted for any resurgence of the domain or related infrastructure, and incident response teams should be prepared to educate users about unsolicited communications that appear to originate from x.com but reference the t-mobile.vthuw.cc address.
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Inteligência forense
Análise do VirusTotal
Evidências e relatórios externos
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo