t-mobile[.]rmhyc[.]cc
“Welcome to nginx!”
t-mobile.rmhyc.cc — 内容不可用 (HTTP 502). 证据摘要: VirusTotal 20/93 (ADMINUSLabs, Criminal IP, alphaMountain.ai, Cluster25, CRDF); PhishDestroy score 95/100. 注册商: Gname.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
The domain t-mobile.rmhyc.cc operates as an impersonation scam site, presenting a page titled "Welcome to nginx!" while claiming to impersonate the brand x.com. This discrepancy between the generic landing page and the targeted brand indicates a potential phishing or credential harvesting threat, where visitors expecting x.com services are deceived into interacting with a fraudulent interface.
Technical analysis reveals the site is flagged by 20 out of 95 VirusTotal vendors, with detections from ADMINUSLabs, Criminal IP, alphaMountain.ai, Cluster25, and CRDF. The domain is registered through Gname.com Pte. Ltd., created on 2026-02-21, and hosted on IP 104.21.62.125 (US) under AS13335 Cloudflare, Inc. It uses nameservers michael.ns.cloudflare.com and nelci.ns.cloudflare.com, with no SSL certificate present, exposing any data transmitted to interception.
As of the analysis, the site is currently DOWN/OFFLINE, with a GridinSoft trust score of 0/100 and a DOM risk score of 10, indicating a high-risk profile despite its inactive state. The presence on one blocklist and the low trust score confirm its malicious nature, posing a residual threat if reactivated.
威胁响应 Pipeline
公共封禁名单状态
VirusTotal 分析
证据与外部报告
PD-20260128-C21587 Recipient: complaint@gname.com 您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。