t-mobile[.]ukwey[.]cc
“Welcome to nginx!”
t-mobile.ukwey.cc — Контент недоступний (HTTP 502). Зведення доказів: VirusTotal 12/93 (ADMINUSLabs, Cluster25, CRDF, CyRadar, Emsisoft); URLQuery 3 alerts; PhishDestroy score 90/100. Реєстратор: Gname.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
Analysis of the domain t-mobile.ukwey.cc reveals infrastructure consistent with brand impersonation targeting x.com. Registered on February 21, 2026, through Gname.com Pte. Ltd., the domain resolved to the IP address 104.21.27.102, hosted on Cloudflare's network (AS13335) in the United States. Nameservers anna.ns.cloudflare.com and ignacio.ns.cloudflare.com further indicate Cloudflare as the DNS provider. At the time of assessment on July 23, 2026, the domain was offline, displaying only the default page title 'Welcome to nginx!', which suggests either misconfigured or recently deactivated phishing infrastructure.
Detection metrics indicate elevated risk: 12 of 93 security vendors on VirusTotal flagged the domain, and it appears on one security blocklist. PhishDestroy has explicitly blocked the domain, while Gridinsoft assigns a trust score of 0/100. The absence of an SSL certificate and the use of a default nginx page title further align with characteristics of phishing campaigns, though the exact content served prior to takedown remains unconfirmed. The domain's creation date, registrar, and hosting provider are consistent with patterns observed in transient phishing operations.
Defenders should treat this domain as compromised infrastructure. Network-level blocking of 104.21.27.102 and monitoring of related Cloudflare-hosted domains registered via Gname.com Pte. Ltd. are recommended. Given the domain's offline status and detection history, retrospective analysis of proxy logs for connections to this IP may identify previously undetected compromise. No evidence links this domain to broader campaign clusters beyond the x.com impersonation classification.
Розвіддані з мережевої безпеки
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| OpenDNS | t-mobile.ukwey.cc |
phishing | Phishing Block |
| DNS4EU | t-mobile.ukwey.cc |
malicious | Sinkholed |
| Hagezi Threat Feed | t-mobile.ukwey.cc |
malicious | Sinkholed |
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Аналіз VirusTotal
Докази та зовнішні звіти
PD-20260202-418D66 Recipient: complaint@gname.com Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога