t-mobile[.]whsgj[.]cc
“Welcome to nginx!”
t-mobile.whsgj.cc — 内容不可用 (HTTP 502). 证据摘要: VirusTotal 11/93 (alphaMountain.ai, Cluster25, CRDF, Emsisoft, Forcepoint ThreatSeeker); URLQuery 4 alerts; PhishDestroy score 83/100. 注册商: Gname.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
The domain t-mobile.whsgj.cc, which impersonates x.com, has been taken offline. Despite its current status, it was flagged as malicious by 15 out of 93 vendors on VirusTotal. PhishDestroy detected this domain on January 24, 2026, shortly after its creation on January 22, 2026. This quick detection highlights the efficiency of PhishDestroy's threat intelligence pipeline.
The domain was registered through Gname.com Pte. Ltd. and hosted on an IP address managed by Cloudflare, Inc., located in the United States. The page displayed a generic 'Welcome to nginx!' message, which is often a placeholder for phishing sites under development or awaiting further configuration. The lack of an SSL certificate further indicates its illegitimacy.
This domain's impersonation of x.com is a typical tactic used in phishing schemes to deceive users into divulging sensitive information. The presence of the brand x.com on the page confirms the intent to mislead visitors. Although the site is now offline, its brief operational period underscores the importance of rapid detection and response in mitigating phishing threats. The domain's inclusion in PhishDestroy's blocklist and its low platform risk score of 10/100 reflect its limited impact before being neutralized.
网络安全情报
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| OpenDNS | t-mobile.whsgj.cc |
phishing | Phishing Block |
| DNS4EU | t-mobile.whsgj.cc |
malicious | Sinkholed |
| Hagezi Threat Feed | t-mobile.whsgj.cc |
malicious | Sinkholed |
| Quad9 DNS | t-mobile.whsgj.cc |
malicious | Sinkholed |
威胁响应 Pipeline
公共封禁名单状态
VirusTotal 分析
证据与外部报告
PD-20260124-264B22 Recipient: complaint@gname.com 您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。