att[.]lydbt[.]cc
“Welcome to nginx!”
Kanıt özeti
The domain att.lydbt.cc was registered on 21 February 2026 through Gname.com Pte. Ltd. and is currently listed as offline. DNS resolution points to 188.114.96.3, an address owned by Cloudflare, Inc. (AS13335) and geolocated to the United States. The authoritative name servers are henry.ns.cloudflare.com and ulla.ns.cloudflare.com, indicating that the infrastructure is hosted behind Cloudflare’s CDN. No TLS certificate is presented; HTTP requests receive the default “Welcome to nginx!” page title, suggesting the server is delivering a generic web server response rather than a targeted login portal. Threat intelligence shows the domain is classified as a brand‑impersonation campaign targeting x.com.
VirusTotal analysis flagged the domain in 12 of 93 vendor engines, and the Gridinsoft trust score is 0 / 100, reflecting a high confidence of malicious intent. The domain appears on a single external blocklist and has been actively blocked by PhishDestroy. The lack of a valid SSL certificate, combined with the generic nginx title, may be an attempt to evade automated content inspection while retaining the ability to host malicious payloads. Uncertainty remains regarding the specific payload or phishing page content because no detailed page scrape is available. Analysts cannot confirm whether credential‑stealing forms or redirect chains were present before the takedown.
The presence of Cloudflare as the front‑end service does not reveal the origin of any back‑end server that may have hosted malicious code. Defenders should add att.lydbt.cc to URL filtering rules, block the associated IP address 188.114.96.3, and monitor for any new subdomains under the same registrar or name‑server pair. Continuous observation of Cloudflare‑originating traffic for anomalous request patterns is advised. Updating endpoint protection and email security gateways with the observed VirusTotal detection signatures will help reduce exposure to any future re‑use of this infrastructure.
Gönderilen kanıt anlık görüntüsü
- Gönderildi
- Kayıt defteri kayıtları
- 1
- Vaka kimliği
PD-20260119-5FDDD7- PDF belgesi
- PDF kanıtı
Kanıtın tam metni
Policy Violations: Illegal Activities section forbids phishing, fraud, fake sites, malware distribution; registrar investigates and may suspend or delete domain
Applicable Laws: Computer Misuse Act 1993 §§3+, Penal Code §§415–420 (cheating), Online Criminal Harms Act (OCHA)
Data Coverage
Ağ Güvenliği İstihbaratı
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| OpenDNS | att.lydbt.cc |
phishing | Phishing Block |
| DNS4EU | att.lydbt.cc |
malicious | Sinkholed |
| Hagezi Threat Feed | att.lydbt.cc |
malicious | Sinkholed |
Tehdit Müdahale Pipeline
Engelleme listesi kapsamı
10 izlenen harici kaynak · kayıtlı anlık görüntü 11.08.2026
Tespit zaman çizelgesi
-
Cloudflare Radar
Cloudflare Radar taraması kaydedildi · Taramayı aç
VirusTotal Analizi
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin