t-mobile[.]pwtmj[.]icu
“Security Verification - Please Wait”
t-mobile.pwtmj.icu — المحتوى غير متوفر (HTTP 502). ملخص الأدلة: VirusTotal 12/93 (ADMINUSLabs, Criminal IP, Cluster25, CRDF, CyRadar); PhishDestroy score 86/100.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
Analysis indicates that the domain t-mobile.pwtmj.icu was registered on 21 February 2026 and is currently taken offline. The site presented the page title “Security Verification – Please Wait,” a common lure used in credential‑harvesting campaigns. Infrastructure inspection shows the domain resolves to IP address 188.114.96.3, which belongs to the Cloudflare network (AS13335) and is geolocated in the United States. The SSL certificate presented is identified as “WE1,” providing no indication of a trusted certificate authority.
Reputation services rate the domain poorly: Gridinsoft assigns a trust score of 0 / 100, and Scamadviser also reports a score of 0 / 100. The domain appears on one public security blocklist and has been actively blocked by PhishDestroy. VirusTotal analysis recorded 12 detections out of 93 scanning engines, confirming that a subset of security vendors consider the site malicious. No further intelligence such as OTX tags, Safe Browsing status, or additional host‑based indicators is available.
Because the site is offline, live interaction cannot be verified, but the combination of a freshly created domain, low trust scores, blocklist presence, and multiple vendor detections strongly suggests a phishing operation targeting users who might believe they are interacting with a T‑Mobile verification page. Defenders should continue to block the domain at network perimeter and DNS layers, monitor for any residual traffic to the associated IP address, and update detection signatures to include the observed page title and certificate fingerprint. Continued observation of the IP range owned by Cloudflare is advised, as the infrastructure may be reused for related campaigns.
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
لقطة محفوظة
معلومات النطاق
التفاصيل الفنيةDNS، أسماء المجال البديلة (SAN) في بروتوكول SSL، الطوابع الزمنية
نطاق SHORTDOT · أدلة عامة
.icu
ShortDot zone evidence
ShortDot zone evidence
The linked repository preserves daily zone observations across seven ShortDot-operated TLDs, including registration volume and abuse-related indicators. This registry context is supporting background and is not an independent detection for the domain in this report.
الاستخبارات الجنائية الرقمية
تحليل VirusTotal
الأدلة والتقارير الخارجية
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب