verizon[.]tfxnja[.]cc
“Welcome to nginx!”
verizon.tfxnja.cc — İçerik kullanılamıyor (HTTP 502). Kanıt özeti: VirusTotal 16/93 (ADMINUSLabs, alphaMountain.ai, BitDefender, Cluster25, CRDF); URLQuery 2 alerts; Spamhaus DBL_PHISH; PhishDestroy score 95/100. Kayıt kuruluşu: Gname.
Özgün adli kaydı korumak için aşağıdaki ayrıntılı PhishDestroy AI analizi İngilizce bırakılmıştır.
The domain verizon.tfxnja.cc was registered on February 21, 2026 through Gname.com Pte. Ltd. and is hosted on Cloudflare infrastructure (AS13335) with the IP address 188.114.96.3 located in the United States. DNS resolution uses the Cloudflare nameservers lorna.ns.cloudflare.com and michael.ns.cloudflare.com. No TLS certificate is presented, and an HTTP request returns the generic page title "Welcome to nginx!", indicating a default web server response rather than a tailored phishing landing page. The site is classified as a Brand Impersonation campaign targeting the x.com brand, and it has been actively blocked by the PhishDestroy blocklist.
Threat intelligence aggregators have flagged the domain: sixteen of ninety‑three VirusTotal scanners reported malicious activity, and Gridinsoft assigns a trust score of zero out of one hundred, reflecting extreme suspicion. The domain appears on one additional security blocklist, reinforcing its malicious reputation. Current operational status is offline, suggesting the hosting may have been taken down or the site is no longer serving content.
Uncertainty remains regarding the specific payload or credential‑harvesting mechanisms, as no login page or phishing content has been captured. Defenders should continue to block the domain at network perimeters, update URL filtering rules, and monitor for any re‑registration attempts or similar sub‑domains that reuse the same naming pattern. Additional analysis of any future HTTP responses or TLS certificates is recommended to confirm whether the infrastructure is repurposed for new campaigns.
Ağ Güvenliği İstihbaratı
Tehdit Müdahale Pipeline
Genel Engelleme Listesi Durumu
VirusTotal Analizi
Kanıtlar ve Dış Raporlar
PD-20260122-AF927D Recipient: complaint@gname.com Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin