t-mobile[.]sbyue[.]cc
“Welcome to nginx!”
t-mobile.sbyue.cc — المحتوى غير متوفر (HTTP 502). ملخص الأدلة: VirusTotal 13/93 (ADMINUSLabs, alphaMountain.ai, Cluster25, CRDF, CyRadar); PhishDestroy score 89/100. مسجّل النطاق: Gname.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
The domain t-mobile.sbyue.cc was registered on February 21, 2026 through Gname.com Pte. Ltd. and is currently flagged as a brand impersonation targeting x.com. DNS resolution points to the IPv6 address 2606:4700:3032::ac43:8ce2, which belongs to Cloudflare, Inc. (AS13335) and is geolocated in the United States. The authoritative nameservers are bristol.ns.cloudflare.com and quentin.ns.cloudflare.com, confirming the use of Cloudflare's DNS infrastructure. An HTTP request returns the default page title "Welcome to nginx!" and no SSL certificate is presented, indicating an unencrypted service. The site was assessed by VirusTotal, where 13 of 93 security vendors reported the domain as malicious.
Independent analysis assigns a Gridinsoft trust score of 0 out of 100, reflecting a lack of trustworthiness. The domain appears on a single security blocklist and has been actively blocked by the PhishDestroy remediation service. Its operational status is listed as offline, but the presence of the domain in multiple detection mechanisms suggests that the infrastructure may be reused or reactivated. Defenders should add t-mobile.sbyue.cc to network deny lists, enforce DNS sinkholing for the associated IPv6 address, and ensure that any email or web traffic claiming to originate from x.com is scrutinized.
Continuous monitoring of the Cloudflare IP range for similar impersonation attempts is advised, as the hosting provider can host a large volume of unrelated legitimate services. Organizations should also update endpoint protection signatures to incorporate the 13 vendor detections reported by VirusTotal, and verify that any internal reference to the domain is blocked at the firewall or proxy level. Because the site lacks an SSL certificate, interception of clear‑text traffic can be used for further intelligence gathering if the domain reappears. Maintaining awareness of the registrar Gname.com Pte. Ltd. may aid in future attribution efforts.
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
تحليل VirusTotal
الأدلة والتقارير الخارجية
PD-20260122-45144E Recipient: complaint@gname.com هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب