att[.]jxdin[.]cc
“Holiday Deals 2025 | AT&T”
Зведення доказів
The domain att.jxdin.cc was registered on 26 January 2026 through Gname.com Pte. Ltd. and is hosted on the Cloudflare network (AS13335) with the address 172.67.179.220, a US‑based edge node. DNS resolution is provided by the authoritative pair A.SHARE-DNS.COM and B.SHARE-DNS.NET. The site presented a page titled “Holiday Deals 2025 | AT&T”, yet the intelligence tags the operation as a “Tech Support Scam” that impersonates Apple. The SSL certificate listed as WE1 is valid for the host, indicating that TLS termination is performed by Cloudflare rather than the malicious operator. Reputation metrics are extremely low: Gridinsoft assigns a score of 0 / 100 and Scamadviser a score of 1 / 100.
The domain appears on a single public blocklist and is actively blocked by PhishDestroy. VirusTotal analysis shows that 16 out of 93 scanning engines flagged the domain, reinforcing the malicious assessment. No additional public safe‑browsing or OTX entries are present in the supplied data. The current operational status is offline, which limits immediate observation of payloads or redirects, but the combination of a brand‑impersonating page title, low trust scores, blocklist presence, and multiple vendor detections indicates a high likelihood of credential‑harvesting or remote‑access social engineering.
Uncertainties remain regarding the exact content served before takedown and whether any C2 infrastructure was leveraged. Defenders should add att.jxdin.cc to internal block or deny lists, monitor for any residual traffic to the Cloudflare IP, and enforce strict email and web filtering for Apple‑related phishing attempts. Continuous observation of the associated IP range and the hosting provider’s abuse channels is advised, as the attacker may shift to new domains using the same infrastructure. Incident response teams should also verify that any user‑reported contacts claiming Apple support are correlated with this domain to facilitate rapid containment.
Data Coverage
Процес реагування на загрози Pipeline
Перевірка за блок-листами
10 зовнішніх джерел під наглядом · знімок від 12.08.2026
Криміналістичні дані
Аналіз VirusTotal
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога