t-mobile[.]sgriv[.]cc
“Welcome to nginx!”
t-mobile.sgriv.cc — Контент недоступний (HTTP 502). Зведення доказів: VirusTotal 10/93 (alphaMountain.ai, Cluster25, CRDF, CyRadar, Emsisoft); PhishDestroy score 80/100.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
Analysis of t-mobile.sgriv.cc, a domain created on February 21, 2026, indicates elevated risk due to confirmed brand‑impersonation activity targeting x.com. The domain resolves to IP address 172.67.171.149, which belongs to Cloudflare, Inc. (AS13335) and is geolocated in the United States. Public blocklist data shows the domain appears on one security blocklist and is specifically listed by PhishDestroy as a malicious entry. Gridinsoft assigns a trust score of 0 out of 100, reflecting the lowest possible confidence in legitimacy.
The only observed HTTP response returns the generic page title "Welcome to nginx!", offering no additional context about the payload or user‑facing content. SSL inspection reveals the certificate labeled "WE1", which does not correspond to a recognized corporate or extended validation certificate, further supporting suspicious status. VirusTotal analysis records ten detections out of ninety‑three participating security vendors, confirming that multiple independent scanners have flagged the domain as malicious. Although the site is currently taken offline, the combination of brand impersonation classification, low trust score, blocklist inclusion, and multiple vendor detections suggests a high likelihood of phishing or credential‑stealing intent.
Defenders should continue to block the domain at perimeter firewalls, update URL filtering policies to include the observed IP range, and monitor for any re‑hosting attempts that might reuse the same certificate or page title. Incident response teams should also correlate any internal logs for outbound connections to 172.67.171.149, especially from users accessing x.com, to identify potential exposure. Ongoing vigilance is advised until the domain remains permanently offline.
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Аналіз VirusTotal
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога