t-mobile[.]ojre[.]cc
“Welcome to nginx!”
t-mobile.ojre.cc — المحتوى غير متوفر (HTTP 502). ملخص الأدلة: VirusTotal 11/95 (Cluster25, CRDF, Emsisoft, Forcepoint ThreatSeeker, Fortinet); PhishDestroy score 83/100. مسجّل النطاق: Gname.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
Analysis of the domain t-mobile.ojre.cc indicates that it is currently taken offline but retains a number of malicious indicators. The domain was registered on February 21, 2026 through Gname.com Pte. Ltd. and is hosted on Cloudflare infrastructure, resolving to IP address 104.21.75.136, which belongs to AS13335 Cloudflare, Inc. in the United States. The authoritative nameservers are rachel.ns.cloudflare.com and yew.ns.cloudflare.com, confirming the use of Cloudflare's DNS services. No SSL certificate is presented for the site, and the HTTP response contains the generic page title "Welcome to nginx!", suggesting a default web server configuration rather than a crafted phishing page. The registrar and hosting details, combined with the lack of TLS, are typical of fast‑flux or temporary phishing deployments.
Threat intelligence flags the domain as a brand impersonation targeting x.com. The scam type is explicitly listed as "Brand Impersonation" and the domain appears on at least one security blocklist, specifically PhishDestroy, which has already blocked the host. A reputation assessment by Gridinsoft assigns a trust score of 0 out of 100, indicating the highest level of suspicion. VirusTotal has recorded 11 detections out of 95 scanners, reinforcing the malicious classification.
While the site is offline, the existing artifacts provide sufficient evidence for defensive teams to enact preventive controls. Organizations should add t-mobile.ojre.cc to URL filtering and DNS blocklists, monitor for any future resolution to the same IP range, and enforce TLS inspection policies to capture any potential re‑appearance of the domain under a new certificate. Continuous watch of the Cloudflare IP block for anomalous traffic patterns is advisable, as threat actors often reuse the same hosting provider for related campaigns.
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
تحليل VirusTotal
الأدلة والتقارير الخارجية
PD-20260203-177642 Recipient: complaint@gname.com هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب