att[.]vtyxz[.]cc
“Welcome to nginx!”
Kanıt özeti
Analysis of the domain att.vtyxz.cc indicates an elevated-risk brand-impersonation campaign targeting X.com, currently offline as of July 23, 2026. The domain was registered on February 21, 2026, through Gname.com Pte. Ltd., a registrar frequently observed in phishing operations. Infrastructure analysis reveals Cloudflare hosting (AS13335) with nameservers alfred.ns.cloudflare.com and nancy.ns.cloudflare.com, resolving to IP 172.67.130.155, geolocated in the United States. No SSL certificate is present, and the HTTP response displays the default 'Welcome to nginx!' page title, suggesting either misconfiguration or a placeholder state during the campaign's inactive phase. Detection data shows the domain is flagged by 12 of 93 security vendors on VirusTotal, though the specific detection engines and signatures are not disclosed in available intelligence.
It appears on one security blocklist and is blocked by PhishDestroy. Gridinsoft assigns a trust score of 0/100, reinforcing its classification as malicious. The absence of an SSL certificate and the use of a default server banner may indicate a hastily deployed or low-sophistication operation, though this does not preclude effectiveness in targeted attacks. Defenders should treat this domain as confirmed malicious infrastructure.
Recommended actions include blocking the domain and IP 172.67.130.155 at perimeter security controls, monitoring for internal connections to the domain or associated Cloudflare nameservers, and reviewing logs for prior interactions. Given the domain's offline status, defenders should prioritize retrospective analysis to identify any successful compromises before takedown. The registrar, Gname.com Pte. Ltd., should be monitored for additional malicious registrations, as its history of abuse may warrant heightened scrutiny in threat intelligence workflows. No evidence currently links this domain to a specific phishing kit or payload, and the exact content served to victims remains unanalyzed.
Gönderilen kanıt anlık görüntüsü
- Gönderildi
- Kayıt defteri kayıtları
- 1
- Vaka kimliği
PD-20260120-E3A47F- Yakalanan sayfa başlığı
- Welcome to nginx!
- PDF belgesi
- PDF kanıtı
Kanıtın tam metni
Policy Violations: Illegal Activities section forbids phishing, fraud, fake sites, malware distribution; registrar investigates and may suspend or delete domain
Applicable Laws: Computer Misuse Act 1993 §§3+, Penal Code §§415–420 (cheating), Online Criminal Harms Act (OCHA)
Data Coverage
Ağ Güvenliği İstihbaratı
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | att.vtyxz.cc |
malicious | Sinkholed |
Tehdit Müdahale Pipeline
Engelleme listesi kapsamı
10 izlenen harici kaynak · kayıtlı anlık görüntü 13.08.2026
Tespit zaman çizelgesi
-
Cloudflare Radar
Cloudflare Radar taraması kaydedildi · Taramayı aç
VirusTotal Analizi
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin