t-mobile[.]vidnufh[.]cc
“Welcome to nginx!”
t-mobile.vidnufh.cc — 内容不可用 (HTTP 502). 证据摘要: VirusTotal 18/93 (ADMINUSLabs, BitDefender, Chong Lua Dao, Cluster25, CRDF); URLQuery 2 alerts; PhishDestroy score 95/100. 注册商: Gname.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
This domain, t-mobile.vidnufh.cc, operates as a fraudulent login portal designed to impersonate X.com (formerly Twitter). The site presents a fake authentication interface to trick visitors into entering their account credentials, which are then harvested by threat actors. The stolen credentials may be used for unauthorized account access, financial fraud, or further phishing campaigns targeting the victim's contacts. The domain's infrastructure and content are engineered to mimic legitimate X.com properties, increasing the likelihood of successful deception among unsuspecting users. Analysis indicates this domain was registered on February 21, 2026, through Gname.com Pte. Ltd., a registrar frequently associated with abusive domains. At the time of assessment, 18 out of 95 security vendors on VirusTotal flagged the domain as malicious, with detection labels including phishing and brand impersonation. The domain resolves to IP address 172.67.200.15, hosted on Cloudflare's network (AS13335), which is commonly used to mask the true origin of malicious infrastructure. The absence of an SSL certificate further signals illegitimacy, as modern web services universally employ encryption for secure communication. If you visited t-mobile.vidnufh.cc and entered any credentials, immediate action is required. First, change your X.com password using a separate, trusted device and enable multi-factor authentication if not already active. Review your account for unauthorized activity, including posts, messages, or connected applications. Monitor linked email accounts and financial services for signs of compromise, such as password reset emails or unauthorized transactions. Report the incident to X.com's security team and consider filing a complaint with relevant cybercrime authorities. Avoid interacting with any communications received from the domain, as threat actors may attempt follow-up attacks via email or direct messages.
网络安全情报
威胁响应 Pipeline
公共封禁名单状态
VirusTotal 分析
证据与外部报告
PD-20260203-EBDEEB Recipient: complaint@gname.com 您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。