att[.]qhosm[.]cc
“Welcome to nginx!”
Kanıt özeti
Analysis of the domain att.qhosm.cc indicates a confirmed brand impersonation phishing campaign targeting X.com, with elevated risk classification. The domain was registered on February 21, 2026, through Gname.com Pte. Ltd., a registrar frequently associated with abusive registrations. Infrastructure analysis reveals the domain resolves to IP address 104.21.91.238, hosted on Cloudflare's network (AS13335) in the United States. Nameservers marek.ns.cloudflare.com and savanna.ns.cloudflare.com further confirm Cloudflare as the DNS provider. At the time of assessment, the domain is offline, though prior HTTP responses returned the default page title 'Welcome to nginx!', suggesting misconfigured or placeholder server deployment rather than a fully operational phishing page.
Detection data from July 24, 2026, shows 11 of 93 security vendors on VirusTotal flagging att.qhosm.cc as malicious, while PhishDestroy has explicitly blocked the domain. The domain appears on one additional security blocklist, reinforcing its classification as a phishing threat. No SSL certificate is present, increasing the likelihood of interception or distrust by modern browsers. Gridinsoft's trust score of 0/100 further corroborates the domain's malicious intent, though the absence of additional context—such as phishing kit artifacts or redirect chains—limits deeper attribution. Defenders should treat this domain as a confirmed phishing resource targeting X.com users.
While the domain is currently offline, its infrastructure remains intact, and reactivation is possible. Network-level blocking of 104.21.91.238 and monitoring for related domains registered via Gname.com Pte. Ltd. are recommended. The lack of SSL and the use of Cloudflare infrastructure suggest the campaign may have been in an early or transitional phase at the time of takedown. Further analysis of historical DNS records or passive DNS data could reveal additional related domains or IP associations.
Gönderilen kanıt anlık görüntüsü
- Gönderildi
- Kayıt defteri kayıtları
- 1
- Vaka kimliği
PD-20260203-6582B7- PDF belgesi
- PDF kanıtı
Kanıtın tam metni
Policy Violations: Illegal Activities section forbids phishing, fraud, fake sites, malware distribution; registrar investigates and may suspend or delete domain
Applicable Laws: Computer Misuse Act 1993 §§3+, Penal Code §§415–420 (cheating), Online Criminal Harms Act (OCHA)
Data Coverage
Tehdit Müdahale Pipeline
Engelleme listesi kapsamı
10 izlenen harici kaynak · kayıtlı anlık görüntü 13.08.2026
Tespit zaman çizelgesi
-
Cloudflare Radar
Cloudflare Radar taraması kaydedildi · Taramayı aç
VirusTotal Analizi
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin