att[.]kgeyu[.]cc
“Welcome to nginx!”
Зведення доказів
Analysis of the domain att.kgeyu.cc was performed on July 23, 2026. The domain is currently offline, which suggests the operators have taken the site down after detection. The domain was registered on March 2, 2026 through Gname.com Pte. Ltd., a registrar that is frequently used for short‑lived malicious infrastructure. DNS resolution points to the IP address 172.67.173.162, which belongs to AS13335 Cloudflare, Inc. and is geolocated in the United States. The authoritative nameservers are benedict.ns.cloudflare.com and melinda.ns.cloudflare.com, confirming that the domain relied on Cloudflare’s DNS and CDN services. No TLS certificate was presented for the site, indicating that the service was delivered over plain HTTP.
An HTTP request to the host returned the default server banner “Welcome to nginx!”, which is a generic response and provides no indication of the intended phishing content. Google Safe Browsing has classified the URL as a social‑engineering threat, and the domain appears on a single security blocklist. PhishDestroy also listed the domain as blocked. VirusTotal recorded 18 detections out of 93 scanned security vendors, reinforcing the view that the domain was used for malicious purposes. The available evidence confirms that att.kgeyu.cc was employed in a generic phishing campaign, but the specific target brand, credential‑capture page layout, or lure technique has not been disclosed in the collected data.
Consequently, defenders cannot attribute the campaign to a particular industry or victim profile beyond the generic phishing classification. The lack of a TLS certificate and the use of a default Nginx page suggest that the malicious site may have been a temporary drop‑off point for redirects or payload delivery rather than a fully crafted phishing landing page.
Знімок надісланих доказів
- Надіслано
- Записи журналу
- 1
- ID справи
PD-20260302-1F47BE- Заголовок збереженої сторінки
- Welcome to nginx!
- PDF-файл
- PDF із доказами
Повний текст доказів
Policy Violations: Illegal Activities section forbids phishing, fraud, fake sites, malware distribution; registrar investigates and may suspend or delete domain
Applicable Laws: Computer Misuse Act 1993 §§3+, Penal Code §§415–420 (cheating), Online Criminal Harms Act (OCHA)
Data Coverage
Розвіддані з мережевої безпеки
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Cloudflare DNS | att.kgeyu.cc |
malicious | Sinkholed |
| DNS4EU | att.kgeyu.cc |
malicious | Sinkholed |
Процес реагування на загрози Pipeline
Перевірка за блок-листами
10 зовнішніх джерел під наглядом · знімок від 13.08.2026
Хронологія виявлення
-
Cloudflare Radar
Сканування Cloudflare Radar збережено · Відкрити сканування
-
Статус домену
Доступний → Недоступний
-
Cloudflare Radar
Сканування Cloudflare Radar збережено · Відкрити сканування
Аналіз VirusTotal
Аналіз продуктивності сайту
Google PageSpeed Insights — mobile performance audit of att.kgeyu.cc · checked Mar 2, 2026
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога