att[.]lydbt[.]cc
“Welcome to nginx!”
证据摘要
The domain att.lydbt.cc was registered on 21 February 2026 through Gname.com Pte. Ltd. and is currently listed as offline. DNS resolution points to 188.114.96.3, an address owned by Cloudflare, Inc. (AS13335) and geolocated to the United States. The authoritative name servers are henry.ns.cloudflare.com and ulla.ns.cloudflare.com, indicating that the infrastructure is hosted behind Cloudflare’s CDN. No TLS certificate is presented; HTTP requests receive the default “Welcome to nginx!” page title, suggesting the server is delivering a generic web server response rather than a targeted login portal. Threat intelligence shows the domain is classified as a brand‑impersonation campaign targeting x.com.
VirusTotal analysis flagged the domain in 12 of 93 vendor engines, and the Gridinsoft trust score is 0 / 100, reflecting a high confidence of malicious intent. The domain appears on a single external blocklist and has been actively blocked by PhishDestroy. The lack of a valid SSL certificate, combined with the generic nginx title, may be an attempt to evade automated content inspection while retaining the ability to host malicious payloads. Uncertainty remains regarding the specific payload or phishing page content because no detailed page scrape is available. Analysts cannot confirm whether credential‑stealing forms or redirect chains were present before the takedown.
The presence of Cloudflare as the front‑end service does not reveal the origin of any back‑end server that may have hosted malicious code. Defenders should add att.lydbt.cc to URL filtering rules, block the associated IP address 188.114.96.3, and monitor for any new subdomains under the same registrar or name‑server pair. Continuous observation of Cloudflare‑originating traffic for anomalous request patterns is advised. Updating endpoint protection and email security gateways with the observed VirusTotal detection signatures will help reduce exposure to any future re‑use of this infrastructure.
已提交证据快照
- 已发送
- 台账记录
- 1
- 案件 ID
PD-20260119-5FDDD7- PDF 文件
- PDF 证据
完整证据文本
Policy Violations: Illegal Activities section forbids phishing, fraud, fake sites, malware distribution; registrar investigates and may suspend or delete domain
Applicable Laws: Computer Misuse Act 1993 §§3+, Penal Code §§415–420 (cheating), Online Criminal Harms Act (OCHA)
Data Coverage
网络安全情报
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| OpenDNS | att.lydbt.cc |
phishing | Phishing Block |
| DNS4EU | att.lydbt.cc |
malicious | Sinkholed |
| Hagezi Threat Feed | att.lydbt.cc |
malicious | Sinkholed |
威胁响应 Pipeline
阻止列表覆盖
监控中的外部数据源 10 个 · 已存快照 2026年8月12日
检测时间线
-
Cloudflare Radar
已存储 Cloudflare Radar 扫描 · 打开扫描
社区报告
由 1 名社区成员报告;首次发现于 2026年1月19日
- 已存储报告
- 1
- 已报告的唯一 URL
- 1
VirusTotal 分析
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。
检查任意域名
使用存储的阻止列表、WHOIS、DNS 和公共扫描证据进行威胁分析
立即扫描举报网络钓鱼
将可疑域名提交至我们的威胁数据库——保护社区
报告实时威胁动态
最近的网络钓鱼报告和观察到的可用性变化
监控