t-mobile[.]hztkv[.]cc
“Welcome to nginx!”
t-mobile.hztkv.cc — 内容不可用 (HTTP 502). 证据摘要: VirusTotal 19/93 (ADMINUSLabs, Criminal IP, Chong Lua Dao, Cluster25, CRDF); PhishDestroy score 95/100. 注册商: Gname.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
This report analyzes the domain t-mobile.hztkv.cc, which was identified as an impersonation of x.com. The site presented a page title of "Welcome to nginx!" and was categorized as an impersonation scam. The threat posed is that the domain attempted to deceive users by mimicking the legitimate x.com brand, likely to harvest credentials or propagate other fraudulent activities.
Technical evidence includes a VirusTotal detection rate of 19 out of 95 vendors flagging the domain as malicious. The domain was flagged by ADMINUSLabs, Criminal IP, Chong Lua Dao, Cluster25, and CRDF. It has 1 blocklist entry. The IP address is 104.21.3.20, located in the United States, associated with AS13335 Cloudflare, Inc. The registrar is Gname.com Pte. Ltd., and the domain was created on 2026-02-21. No SSL certificate was detected. The nameservers are colette.ns.cloudflare.com and donald.ns.cloudflare.com. The GridinSoft trust score is 0 out of 100, and the DOM risk score is 10.
The domain is currently down or offline. The risk level is high based on the 0/100 trust score, 10 DOM risk score, and 19/95 VirusTotal detection rate, indicating a malicious intent. The impersonation of x.com and the lack of SSL further elevate the threat, though the site is no longer accessible.
威胁响应 Pipeline
公共封禁名单状态
VirusTotal 分析
证据与外部报告
PD-20260130-3E8FD3 Recipient: complaint@gname.com 您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。