att[.]qatio[.]cc
“Welcome to nginx!”
Зведення доказів
Analysis of the domain att.qatio.cc shows a newly registered site created on February 21, 2026 that has been taken offline as of the report date. The domain resolves to the IP address 172.67.161.61, which belongs to the Cloudflare network (AS13335) and is geolocated in the United States. Nameserver records point to henry.ns.cloudflare.com and ulla.ns.cloudflare.com, confirming the use of Cloudflare’s DNS infrastructure. The registrar listed is Gname.com Pte. Ltd. No TLS certificate is presented; the HTTP response returns the default "Welcome to nginx!" page title, indicating that no custom web content was observed before the takedown.
Threat intelligence flags the site as a brand‑impersonation campaign targeting x.com. Twelve of ninety‑five VirusTotal scanners flagged the domain, and it appears on a single external blocklist. The Gridinsoft trust score is 0 out of 100, reinforcing the malicious assessment. PhishDestroy has already blocked the domain, and the current status is offline, suggesting the operators have withdrawn the site, possibly to avoid further detection.
Uncertainty remains around any payload or credential‑harvesting infrastructure that may have been hosted behind the domain before takedown, as no further page content or redirects were captured. Defenders should continue to block the IP 172.67.161.61 at the network perimeter, add att.qatio.cc to local and cloud‑based URL filtering lists, and monitor for re‑registration of similar sub‑domains under the same registrar or using the same Cloudflare nameservers. Ongoing scrutiny of Cloudflare‑hosted assets targeting the x.com brand is advised, as the infrastructure could be repurposed for future impersonation attempts.
Знімок надісланих доказів
- Надіслано
- Записи журналу
- 1
- ID справи
PD-20260119-2A0D31- PDF-файл
- PDF із доказами
Повний текст доказів
Policy Violations: Illegal Activities section forbids phishing, fraud, fake sites, malware distribution; registrar investigates and may suspend or delete domain
Applicable Laws: Computer Misuse Act 1993 §§3+, Penal Code §§415–420 (cheating), Online Criminal Harms Act (OCHA)
Data Coverage
Розвіддані з мережевої безпеки
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| OpenDNS | att.qatio.cc |
phishing | Phishing Block |
| DNS4EU | att.qatio.cc |
malicious | Sinkholed |
| Hagezi Threat Feed | att.qatio.cc |
malicious | Sinkholed |
| Quad9 DNS | att.qatio.cc |
malicious | Sinkholed |
Процес реагування на загрози Pipeline
Перевірка за блок-листами
10 зовнішніх джерел під наглядом · знімок від 10.08.2026
Хронологія виявлення
-
Cloudflare Radar
Сканування Cloudflare Radar збережено · Відкрити сканування
Аналіз VirusTotal
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога