att[.]ybpge[.]cc
“Welcome to nginx!”
att.ybpge.cc — 内容不可用. 证据摘要: VirusTotal 16/93 (Criminal IP, BitDefender, Cluster25, CRDF, CyRadar); PhishDestroy score 95/100. 注册商: Gname.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
The domain att.ybpge.cc has been identified as a brand impersonation threat specifically targeting X.com. As of the latest assessment, this domain is currently offline, but its registration and hosting details reveal a clear attempt to deceive users through phishing tactics. The domain was created on February 21, 2026, through the registrar Gname.com Pte. Ltd., and resolves to the IP address 104.21.63.4. Notably, it lacks an SSL certificate, which is a significant red flag for any site claiming to represent a legitimate brand like X.com.
Security analysis shows that att.ybpge.cc has been flagged by 16 out of 95 VirusTotal vendors, indicating broad recognition as malicious within the security community. Additionally, it appears on one security blocklist, and the page title displayed is simply "Welcome to nginx!"—a generic placeholder that further suggests the site is not actively serving legitimate content. The combination of these factors, including the brand impersonation target and the lack of encryption, points to a high-risk domain designed to harvest credentials or spread malware.
Given that the domain is currently offline, immediate action may not be necessary, but users should remain vigilant. PhishDestroy recommends that anyone who may have interacted with att.ybpge.cc or similar domains should monitor their accounts for suspicious activity and change passwords if any credentials were entered. Organizations should also ensure their security tools block this domain and educate users about the risks of brand impersonation phishing. Always verify website URLs before providing personal information, especially when the site lacks HTTPS or exhibits unusual domain names like att.ybpge.cc.
威胁响应 Pipeline
公共封禁名单状态
VirusTotal 分析
证据与外部报告
PD-20260119-E074FB Recipient: complaint@gname.com 您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。