t-mobile[.]cwtoa[.]cc
“Welcome to nginx!”
t-mobile.cwtoa.cc — Контент недоступен (HTTP 502). Сводка доказательств: VirusTotal 18/95 (ADMINUSLabs, Criminal IP, alphaMountain.ai, Cluster25, CRDF); URLQuery 4 alerts; PhishDestroy score 95/100. Регистратор: Gname.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
This domain, t-mobile.cwtoa.cc, is flagged for brand impersonation targeting x.com, a high-value social media platform. Analysis indicates the site was designed to deceive users into believing they were interacting with official x.com services, likely for credential theft or fraudulent account access. No crypto drainer kit signatures were detected in available telemetry, but the domain's infrastructure and registration patterns align with known brand abuse campaigns. Infrastructure analysis reveals the following technical indicators: the domain was registered on February 21, 2026, through Gname.com Pte. Ltd., a registrar frequently associated with malicious registrations. It resolves to IP address 104.21.15.6, hosted on Cloudflare's network (AS13335), which is commonly exploited to obfuscate attacker infrastructure. The domain appears on one security blocklist and is flagged by 18 out of 95 security vendors on VirusTotal. No SSL certificate was observed, and the page title displayed a default "Welcome to nginx!" message, suggesting either incomplete deployment or rapid takedown. The domain is currently offline, likely due to enforcement actions by hosting providers or security teams. However, residual risk remains due to the domain's recent creation and the potential for re-activation under new infrastructure. Organizations should monitor for DNS changes, SSL certificate issuance, or renewed resolution to Cloudflare or other bulletproof hosting providers. Users who may have interacted with this domain should verify account integrity, enable multi-factor authentication, and review connected applications for unauthorized access. Proactive blocking of the domain and its associated IP at the network level is recommended to prevent future exposure.
Данные сетевой безопасности
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| OpenDNS | t-mobile.cwtoa.cc |
phishing | Phishing Block |
| DNS4EU | t-mobile.cwtoa.cc |
malicious | Sinkholed |
| Hagezi Threat Feed | t-mobile.cwtoa.cc |
malicious | Sinkholed |
| Quad9 DNS | t-mobile.cwtoa.cc |
malicious | Sinkholed |
Процесс реагирования на угрозы
Статус в публичных блок-листах
Анализ VirusTotal
Доказательства и внешние отчеты
PD-20260124-8AA0F7 Recipient: complaint@gname.com Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание