t-mobile[.]qaxvb[.]cc
“Welcome to nginx!”
t-mobile.qaxvb.cc — İçerik kullanılamıyor (HTTP 502). Kanıt özeti: VirusTotal 18/93 (ADMINUSLabs, Criminal IP, BitDefender, Cluster25, CRDF); Spamhaus DBL_PHISH; PhishDestroy score 95/100. Kayıt kuruluşu: Dominet (HK).
Özgün adli kaydı korumak için aşağıdaki ayrıntılı PhishDestroy AI analizi İngilizce bırakılmıştır.
This domain is flagged for elevated-risk brand impersonation, specifically targeting x.com through deceptive infrastructure. Analysis indicates the site was designed to mimic legitimate login portals, likely to harvest credentials or distribute malicious payloads under the guise of a trusted platform. The threat type aligns with targeted phishing campaigns exploiting brand recognition to bypass user vigilance. Infrastructure analysis reveals the domain was registered on February 21, 2026, through Dominet (HK) Limited, a registrar frequently associated with high-risk domains. It resolves to IP 8.219.239.111, hosted on Alibaba (US) Technology Co., Ltd. infrastructure (AS45102) in Singapore. Security vendor detections on VirusTotal reached 18/95, with the domain appearing on at least one security blocklist. The absence of an SSL certificate and the default nginx welcome page suggest either an incomplete deployment or a placeholder for future malicious activity. No historical content was captured prior to takedown, limiting forensic reconstruction. Mitigation steps for this threat type include blocking the domain and its resolving IP at network perimeter controls. Organizations should monitor for credential reuse attempts from harvested accounts, particularly those associated with x.com. Endpoint detection rules should prioritize alerts for connections to newly registered domains under offshore registrars, especially those mimicking high-value brands. Security teams are advised to correlate this domain with other indicators from the same registrar or hosting provider to identify potential campaign clusters. User awareness training should emphasize verification of domain authenticity before entering credentials, even when pages appear visually legitimate.
Tehdit Müdahale Pipeline
Genel Engelleme Listesi Durumu
VirusTotal Analizi
Kanıtlar ve Dış Raporlar
PD-20260122-2693E8 Recipient: domainabuse@service.aliyun.com Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin