t-mobile[.]ukwey[.]cc
“Welcome to nginx!”
t-mobile.ukwey.cc — Контент недоступен (HTTP 502). Сводка доказательств: VirusTotal 12/93 (ADMINUSLabs, Cluster25, CRDF, CyRadar, Emsisoft); URLQuery 3 alerts; PhishDestroy score 90/100. Регистратор: Gname.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
Analysis of the domain t-mobile.ukwey.cc reveals infrastructure consistent with brand impersonation targeting x.com. Registered on February 21, 2026, through Gname.com Pte. Ltd., the domain resolved to the IP address 104.21.27.102, hosted on Cloudflare's network (AS13335) in the United States. Nameservers anna.ns.cloudflare.com and ignacio.ns.cloudflare.com further indicate Cloudflare as the DNS provider. At the time of assessment on July 23, 2026, the domain was offline, displaying only the default page title 'Welcome to nginx!', which suggests either misconfigured or recently deactivated phishing infrastructure.
Detection metrics indicate elevated risk: 12 of 93 security vendors on VirusTotal flagged the domain, and it appears on one security blocklist. PhishDestroy has explicitly blocked the domain, while Gridinsoft assigns a trust score of 0/100. The absence of an SSL certificate and the use of a default nginx page title further align with characteristics of phishing campaigns, though the exact content served prior to takedown remains unconfirmed. The domain's creation date, registrar, and hosting provider are consistent with patterns observed in transient phishing operations.
Defenders should treat this domain as compromised infrastructure. Network-level blocking of 104.21.27.102 and monitoring of related Cloudflare-hosted domains registered via Gname.com Pte. Ltd. are recommended. Given the domain's offline status and detection history, retrospective analysis of proxy logs for connections to this IP may identify previously undetected compromise. No evidence links this domain to broader campaign clusters beyond the x.com impersonation classification.
Данные сетевой безопасности
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| OpenDNS | t-mobile.ukwey.cc |
phishing | Phishing Block |
| DNS4EU | t-mobile.ukwey.cc |
malicious | Sinkholed |
| Hagezi Threat Feed | t-mobile.ukwey.cc |
malicious | Sinkholed |
Процесс реагирования на угрозы
Статус в публичных блок-листах
Анализ VirusTotal
Доказательства и внешние отчеты
PD-20260202-418D66 Recipient: complaint@gname.com Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание