att[.]jowek[.]cc
“Welcome to nginx!”
证据摘要
This report analyzes the domain att.jowek.cc, which was configured to impersonate the brand x.com. The site presented a default "Welcome to nginx!" page title, indicating no functional content was served, but its classification as an impersonation scam suggests it was designed to deceive visitors into believing they were interacting with a legitimate x.com service. The primary threat posed is social engineering, as flagged by Google Safe Browsing, which could lead to credential theft or other fraudulent activities.
Technical evidence shows the domain was flagged by 19 out of 95 VirusTotal vendors, with detections from ADMINUSLabs, Criminal IP, BitDefender, Chong Lua Dao, and Cluster25. Google Safe Browsing explicitly flagged the site for SOCIAL_ENGINEERING. The domain was registered through Gname.com Pte. Ltd. and created on 2026-02-21, with an IP address of 104.21.13.143 hosted in the United States under AS13335 Cloudflare, Inc. The site lacked SSL certification and used nameservers cory.ns.cloudflare.com and gemma.ns.cloudflare.com.
As of analysis, the domain is DOWN/OFFLINE, rendering it inaccessible. However, its DOM risk score of 10 and GridinSoft trust rating of 0 out of 100 indicate a high-risk profile. The domain remains on 1 blocklist, and due to its impersonation nature and confirmed social engineering flag, it poses a significant threat to potential visitors, particularly those expecting legitimate x.com services.
已提交证据快照
- 已发送
- 台账记录
- 1
- 案件 ID
PD-20260130-F4ECD4- 已捕获页面标题
- Welcome to nginx!
- PDF 文件
- PDF 证据
完整证据文本
Policy Violations: Illegal Activities section forbids phishing, fraud, fake sites, malware distribution; registrar investigates and may suspend or delete domain
Applicable Laws: Computer Misuse Act 1993 §§3+, Penal Code §§415–420 (cheating), Online Criminal Harms Act (OCHA)
Data Coverage
威胁响应 Pipeline
阻止列表覆盖
监控中的外部数据源 10 个 · 已存快照 2026年8月13日
检测时间线
-
Cloudflare Radar
已存储 Cloudflare Radar 扫描 · 打开扫描
VirusTotal 分析
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。
检查任意域名
使用存储的阻止列表、WHOIS、DNS 和公共扫描证据进行威胁分析
立即扫描举报网络钓鱼
将可疑域名提交至我们的威胁数据库——保护社区
报告实时威胁动态
最近的网络钓鱼报告和观察到的可用性变化
监控