t-mobile[.]vthuw[.]cc
“Welcome to nginx!”
t-mobile.vthuw.cc — İçerik kullanılamıyor (HTTP 502). Kanıt özeti: VirusTotal 13/93 (ADMINUSLabs, Cluster25, CRDF, CyRadar, Forcepoint ThreatSeeker); Spamhaus DBL_PHISH; PhishDestroy score 89/100.
Özgün adli kaydı korumak için aşağıdaki ayrıntılı PhishDestroy AI analizi İngilizce bırakılmıştır.
The domain t-mobile.vthuw.cc was registered on February 21, 2026 and is currently taken offline. It is listed as a brand impersonation campaign targeting x.com. Infrastructure analysis shows the domain resolves to IP address 172.67.176.58, which belongs to AS13335 Cloudflare, Inc. and is geolocated in the United States. The site presented the default nginx page title "Welcome to nginx!" and used an SSL certificate identified as WE1, suggesting a generic or self‑signed certificate rather than a brand‑validated chain.
Reputation services scored the domain at zero out of one hundred on both Scamadviser and Gridinsoft, indicating a lack of trust. The domain was blocked by the PhishDestroy blocklist and appears on one additional security blocklist. VirusTotal recorded 13 detections out of 93 scanned security vendors, confirming that multiple scanners flagged the host as malicious.
No further content analysis is available because the site is offline, leaving the exact phishing payload or login collection mechanisms unverified. Defenders should immediately add t-mobile.vthuw.cc to network deny lists, monitor for any future resolution to the same Cloudflare IP range, and enforce email and web filtering policies that detect brand impersonation attempts referencing x.com. Continuous threat‑intel feeds should be consulted for any resurgence of the domain or related infrastructure, and incident response teams should be prepared to educate users about unsolicited communications that appear to originate from x.com but reference the t-mobile.vthuw.cc address.
Tehdit Müdahale Pipeline
Genel Engelleme Listesi Durumu
Adli İstihbarat
VirusTotal Analizi
Kanıtlar ve Dış Raporlar
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin