t-mobile[.]sawye[.]cc
t-mobile.sawye.cc — المحتوى غير متوفر (HTTP 502). انتحال العلامة التجارية: Genericcloudflare. ملخص الأدلة: VirusTotal 12/95 (ADMINUSLabs, Cluster25, CRDF, CyRadar, Forcepoint ThreatSeeker); URLScan malicious verdict; Spamhaus DBL_PHISH; PhishDestroy score 86/100.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
t-mobile.sawye.cc was observed in multiple threat feeds as a phishing infrastructure targeting users of a major mobile carrier. The domain was registered on 21 February 2026 and resolves to the Cloudflare address 172.67.212.15, an IP range owned by AS13335 in the United States. The SSL certificate presented for the host is identified as “WE1”, which is commonly associated with short‑lived certificates used by malicious operators. VirusTotal records show that 12 of 95 scanning engines have flagged the domain as malicious, indicating a moderate level of detection across the security community.
The domain appears on a single public blocklist and is actively blocked by the PhishDestroy service, confirming that at least one reputable anti‑phishing repository has catalogued it. Current network measurements indicate that the host is offline, which suggests the operators have taken the site down or are rotating infrastructure. No public page title, brand reference, or additional content has been disclosed, so the exact visual or functional characteristics of the site remain unknown.
Defenders should continue to monitor the IP address 172.67.212.15 for any re‑appearance of malicious content, enforce outbound filtering for URLs containing the “sawye.cc” suffix, and ensure that email gateways block messages containing links to this domain. Because the domain is hosted behind Cloudflare, any future re‑hosting could inherit the same IP range, so reputation‑based controls that consider the AS number and certificate fingerprint are advisable. In the absence of further artifacts, the primary evidence for this threat consists of the registration date, hosting details, SSL certificate, vendor detections, and blocklist inclusion.
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
الاستخبارات الجنائية الرقمية
تحليل VirusTotal
الأدلة والتقارير الخارجية
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب