t-mobile[.]tukqv[.]icu
t-mobile.tukqv.icu — المحتوى غير متوفر (HTTP 502). ملخص الأدلة: VirusTotal 16/93 (ADMINUSLabs, alphaMountain.ai, Cluster25, CRDF, CyRadar); Spamhaus DBL_PHISH; PhishDestroy score 95/100.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
The domain t-mobile.tukqv.icu was registered on February 21, 2026 and is currently listed as offline. VirusTotal scans show that 16 of 93 security vendors have flagged the domain, indicating a moderate level of detection across multiple AV engines. The site presents an SSL certificate identified as WE1, which does not correspond to a recognized public‑trusted CA and may be a self‑signed or otherwise anomalous certificate. DNS resolution points to IP address 172.67.197.185, which belongs to the Cloudflare network (AS13335) and is geolocated in the United States.
The hosting provider therefore offers the typical abstraction and CDN protections associated with Cloudflare, but the IP itself is shared among many unrelated services, limiting attribution to a single threat actor. The domain appears on a single security blocklist and has been actively blocked by the PhishDestroy service, reinforcing the assessment that it is being used for malicious purposes. Additionally, Gridinsoft assigns a trust score of 0 out of 100, effectively rating the domain as completely untrusted. No further details about page content, HTTP response codes, or specific phishing lures are available in the current intelligence set.
Given the combination of vendor detections, low trust score, blocklist inclusion, and a non‑standard SSL certificate, defenders should treat t-mobile.tukqv.icu as a high‑confidence phishing indicator. Recommended mitigation steps include adding the domain to DNS and proxy deny lists, monitoring the associated Cloudflare IP for any re‑use in future campaigns, and ensuring endpoint protection solutions are updated to reflect the 16 vendor detections. Continuous re‑scanning on VirusTotal and similar platforms is advised to capture any changes in classification, and any observed traffic to the domain should be logged and investigated for potential credential harvesting attempts.
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
لقطة محفوظة
معلومات النطاق
التفاصيل الفنيةDNS، أسماء المجال البديلة (SAN) في بروتوكول SSL، الطوابع الزمنية
نطاق SHORTDOT · أدلة عامة
.icu
ShortDot zone evidence
ShortDot zone evidence
The linked repository preserves daily zone observations across seven ShortDot-operated TLDs, including registration volume and abuse-related indicators. This registry context is supporting background and is not an independent detection for the domain in this report.
الاستخبارات الجنائية الرقمية
تحليل VirusTotal
الأدلة والتقارير الخارجية
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب