t-mobile[.]uibhd[.]cc
“Welcome to nginx!”
t-mobile.uibhd.cc — 内容不可用 (HTTP 502). 证据摘要: VirusTotal 15/95 (Criminal IP, alphaMountain.ai, BitDefender, Cluster25, CRDF); PhishDestroy score 95/100. 注册商: Gname.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
This domain, t-mobile.uibhd.cc, was registered on February 21, 2026, through Gname.com Pte. Ltd. and is flagged as a brand impersonation scam targeting x.com. As of July 23, 2026, the domain is offline, though it previously resolved to 172.67.223.224, a Cloudflare IP (AS13335) located in the US. Infrastructure analysis reveals Cloudflare nameservers (damian.ns.cloudflare.com and lia.ns.cloudflare.com) and no SSL certificate. The HTTP response displayed a default 'Welcome to nginx!' page title, indicating either misconfigured or placeholder infrastructure rather than a fully deployed phishing kit.
Detection data shows the domain appears on one security blocklist (PhishDestroy) and is flagged by 15 of 95 security vendors on VirusTotal. Gridinsoft assigns a trust score of 0/100. While the domain is currently inactive, defenders should treat it as elevated risk due to its confirmed impersonation of x.com and prior detection by multiple security tools.
No evidence of credential harvesting or post-login redirection is available, as the exact content was not analysed. Review related IP 172.67.223.224 and nameserver patterns for additional linked infrastructure. If encountered in logs, classify as malicious and block at the network level.
威胁响应 Pipeline
公共封禁名单状态
VirusTotal 分析
证据与外部报告
PD-20260128-DA967D Recipient: complaint@gname.com 您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。