t-mobile[.]ogvzl[.]cc
“ogvzl.cc | 522: Connection timed out”
t-mobile.ogvzl.cc — المحتوى غير متوفر (HTTP 502). انتحال العلامة التجارية: T-mobile; نوع الاحتيال: Brand Impersonation. ملخص الأدلة: VirusTotal 13/93 (ADMINUSLabs, Criminal IP, Cluster25, CRDF, CyRadar); URLQuery 1 alert; Spamhaus DBL_PHISH; PhishDestroy score 89/100. مسجّل النطاق: Gname.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
Analysis of t-mobile.ogvzl.cc, created on February 21, 2026, shows an active brand impersonation campaign targeting T-Mobile. The site is listed on the PhishDestroy blocklist, and 13 of 93 VirusTotal scanners have flagged it as malicious, indicating a consensus among security vendors that the domain is involved in fraudulent activity. The infrastructure is hosted behind Cloudflare, as evidenced by the IPv4 address 172.67.202.6 belonging to AS13335 (Cloudflare, Inc.) and the use of Cloudflare nameservers alexia.ns.cloudflare.com and damian.ns.cloudflare.com.
No SSL certificate is presented, and an HTTP request returns the page title "ogvzl.cc | 522: Connection timed out," confirming that the service is currently unreachable and the domain has been taken offline. The Gridinsoft trust score of 0 out of 100 further reinforces the malicious classification. The phishing kit associated with the domain is identified as an Airdrop Scam, which aligns with the brand impersonation classification.
Defenders should continue to block the domain at perimeter defenses, monitor Cloudflare‑hosted IP ranges for related activity, and watch for newly registered domains that share the same registrar (Gname.com Pte. Ltd.) or similar naming patterns. Because the site is offline, immediate threat to end users is reduced, but the underlying infrastructure may be repurposed for future campaigns, so ongoing observation is recommended.
استخبارات أمن الشبكات
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| OpenDNS | t-mobile.ogvzl.cc |
phishing | Phishing Block |
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
تحليل VirusTotal
الأدلة والتقارير الخارجية
PD-20260118-2E3495 Recipient: complaint@gname.com هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب