att[.]qagcd[.]cc
“Welcome to nginx!”
Kanıt özeti
The domain att.qagcd.cc was registered on 21 February 2026 through Gname.com Pte. Ltd. and is hosted on the Cloudflare network (ASN 13335) with the IP address 188.114.97.3 located in the United States. No TLS certificate is presented; HTTP requests return a default nginx welcome page titled “Welcome to nginx!”. The site has been classified as a brand‑impersonation campaign targeting the X.com brand. Analysis of public blocklists shows the domain is listed on a single security blocklist and has been taken offline by the mitigation service PhishDestroy.
The domain’s trust score from Gridinsoft is 0 out of 100, indicating an extremely low credibility rating. VirusTotal scans report 13 of 93 antivirus engines flagging the domain, reinforcing the suspicion of malicious intent. Nameserver records point to edna.ns.cloudflare.com and jarred.ns.cloudflare.com, both Cloudflare‑controlled. Although the visible HTTP response contains only a generic server banner, the combination of a newly created domain, null SSL, low trust score, multiple vendor detections, and explicit branding of X.com suggests a purposeful attempt to lure credentials or deliver further payloads.
The current offline status prevents immediate interaction, but the infrastructure—particularly the Cloudflare‑origin IP—remains reusable for future impersonation attempts. Defenders should add att.qagcd.cc to deny‑list policies at the DNS and proxy layers, monitor traffic to its resolving IP, and ensure endpoint protection solutions are updated to reflect the 13 vendor detections. Continuous observation of the registrar Gname.com for new domains leveraging the same nameservers is advised, as well as periodic re‑scans should the domain reappear. Until further forensic evidence is obtained, the domain should be treated as an elevated‑risk impersonation vector.
Gönderilen kanıt anlık görüntüsü
- Gönderildi
- Kayıt defteri kayıtları
- 1
- Vaka kimliği
PD-20260120-9FDDBC- Yakalanan sayfa başlığı
- Welcome to nginx!
- PDF belgesi
- PDF kanıtı
Kanıtın tam metni
Policy Violations: Illegal Activities section forbids phishing, fraud, fake sites, malware distribution; registrar investigates and may suspend or delete domain
Applicable Laws: Computer Misuse Act 1993 §§3+, Penal Code §§415–420 (cheating), Online Criminal Harms Act (OCHA)
Data Coverage
Ağ Güvenliği İstihbaratı
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | att.qagcd.cc |
malicious | Sinkholed |
Tehdit Müdahale Pipeline
Engelleme listesi kapsamı
10 izlenen harici kaynak · kayıtlı anlık görüntü 11.08.2026
Tespit zaman çizelgesi
-
Cloudflare Radar
Cloudflare Radar taraması kaydedildi · Taramayı aç
VirusTotal Analizi
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin