t-mobile[.]htrki[.]icu
“Welcome to nginx!”
t-mobile.htrki.icu — 内容不可用 (HTTP 502). 证据摘要: VirusTotal 15/95 (BitDefender, CRDF, CyRadar, ESET, Forcepoint ThreatSeeker); Spamhaus DBL_PHISH; PhishDestroy score 100/100.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
This site, t-mobile.htrki.icu, presents a page titled "Welcome to nginx!" but is classified as an impersonation scam targeting the brand x.com. The threat posed is that it attempts to deceive visitors by presenting itself as a legitimate service, likely to harvest credentials or sensitive information under a false identity.
Technical evidence shows the site was flagged by 15 out of 95 VirusTotal vendors, with detection by BitDefender, CRDF, CyRadar, ESET, and Forcepoint ThreatSeeker. It is listed on 1 blocklist. The domain uses IP address 104.21.79.160, hosted in the US by AS13395 Cloudflare, Inc. It was created on 2026-02-21 and uses SSL certificate type WE1.
The site is currently offline and down. Trust ratings are extremely low, with GridinSoft at 0/100 and ScamAdviser at 1/100, and a DOM risk score of 73, indicating a high-risk, malicious domain.
威胁响应 Pipeline
公共封禁名单状态
已保存的截图
域名情报
技术细节DNS、SSL SAN、时间戳
SHORTDOT 域名区 · 公开证据
.icu
ShortDot zone evidence
ShortDot zone evidence
The linked repository preserves daily zone observations across seven ShortDot-operated TLDs, including registration volume and abuse-related indicators. This registry context is supporting background and is not an independent detection for the domain in this report.
取证情报
VirusTotal 分析
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。