t-mobile[.]wimpu[.]cc
“Welcome to nginx!”
t-mobile.wimpu.cc — المحتوى غير متوفر (HTTP 502). ملخص الأدلة: VirusTotal 20/93 (ADMINUSLabs, Criminal IP, alphaMountain.ai, BitDefender, Cluster25); URLQuery 5 alerts; PhishDestroy score 95/100. مسجّل النطاق: Gname.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
This domain, t-mobile.wimpu.cc, is flagged as an elevated-risk brand impersonation site specifically targeting X.com (formerly Twitter). Analysis indicates the threat actor designed the infrastructure to mimic legitimate X.com authentication portals, likely to harvest user credentials or distribute malicious payloads under the guise of official branding. The use of a deceptive subdomain (t-mobile) suggests an attempt to exploit trust in unrelated brands to increase victim compliance, a tactic commonly observed in credential theft campaigns. Infrastructure analysis reveals the domain was registered on February 21, 2026, through Gname.com Pte. Ltd., a registrar frequently associated with high-risk domains due to lenient registration policies. The domain resolves to IP address 104.21.49.8, hosted on AS13335 (Cloudflare, Inc.), a network often leveraged to obfuscate malicious activity behind content delivery networks. At the time of assessment, the domain appeared on one security blocklist, while VirusTotal detection rates indicated 20 out of 95 security vendors flagged it as malicious. The absence of an SSL certificate further undermines its legitimacy, as modern phishing campaigns typically employ encryption to evade detection. The page title, 'Welcome to nginx!', suggests misconfigured or hastily deployed infrastructure, a common red flag in low-effort phishing operations. Mitigation against this brand impersonation threat requires multi-layered defenses. Network administrators should block resolution to 104.21.49.8 and monitor for domains registered through Gname.com Pte. Ltd. with creation dates around February 2026. End-users should verify domain authenticity by cross-referencing URLs with official X.com communications and inspecting for SSL certificates before entering credentials. Organizations should implement email filtering rules to quarantine messages containing the domain or its IP, while security teams should prioritize hunting for related indicators of compromise, such as unusual login attempts or unexpected OAuth token requests. Given the domain's current offline status, continuous monitoring for re-registration or DNS reactivation is recommended.
استخبارات أمن الشبكات
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| OpenDNS | t-mobile.wimpu.cc |
phishing | Phishing Block |
| Hagezi Threat Feed | t-mobile.wimpu.cc |
malicious | Sinkholed |
| Quad9 DNS | t-mobile.wimpu.cc |
malicious | Sinkholed |
| Cloudflare DNS | t-mobile.wimpu.cc |
malicious | Sinkholed |
| DNS4EU | t-mobile.wimpu.cc |
malicious | Sinkholed |
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
تحليل VirusTotal
الأدلة والتقارير الخارجية
PD-20260125-04238F Recipient: complaint@gname.com هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب