t-mobile[.]hxkwoy[.]shop
“Welcome to OpenResty!”
t-mobile.hxkwoy.shop — Inhalt nicht verfügbar (HTTP 502). Zusammenfassung der Beweislage: VirusTotal 12/91 (Cluster25, CRDF, CyRadar, Emsisoft, Fortinet); Google Safe Browsing flagged; Spamhaus DBL_PHISH; PhishDestroy score 98/100.
Die ausführliche Analyse von PhishDestroy AI bleibt auf Englisch, damit der ursprüngliche forensische Bericht unverändert bleibt.
The domain t-mobile.hxkwoy.shop is identified as a high-risk generic_phishing site, specifically designed to impersonate T-Mobile. This domain is currently offline, indicating a potential takedown or suspension of the malicious activity. However, users and organizations should remain vigilant as such domains can be quickly reactivated or repurposed.
Analysis indicates that the domain t-mobile.hxkwoy.shop was flagged by 12 of 95 VirusTotal vendors, suggesting a moderate level of recognition among security providers. The domain resolves to the IP address 188.114.97.3 and has a Gridinsoft trust score of 0/100, indicating a complete lack of trustworthiness. The page title 'Welcome to OpenResty!' is a common indicator used by attackers to mask the true nature of the domain. Additionally, the domain appears on one security blocklist and is blocked by PhishDestroy. Google Safe Browsing has flagged the domain for social engineering, further corroborating its malicious intent. The use of Cloudflare Browser Insights and HTTP/3 suggests that the attackers are leveraging modern web technologies to enhance the credibility and performance of their phishing infrastructure.
Given the current offline status of the domain, it is recommended that users and security teams continue to monitor for any signs of reactivation. Organizations should ensure that their employees are trained to recognize and report phishing attempts, particularly those impersonating well-known brands like T-Mobile. Network administrators should consider implementing DNS filtering and blocking mechanisms to prevent access to this domain and similar high-risk sites. Regular security audits and updates to phishing detection tools can also help mitigate the risk of such threats.
Erkenntnisse zur Netzwerksicherheit
Pipeline zur Reaktion auf Sicherheitsbedrohungen
Status der öffentlichen Sperrliste
Technologien · 3 identified
Cloudflare Browser Insights is a tool that measures the performance of websites from the perspective of users.
www.cloudflare.com 100 % KonfidenzCloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100 % KonfidenzHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100 % KonfidenzVirusTotal-Analyse
Archivierte Beweise
Website-Performanceanalyse
Google PageSpeed Insights — mobile performance audit of t-mobile.hxkwoy.shop · checked Jun 25, 2026
Nachweise und externe Berichte
Wurden Sie von dieser Website betroffen?
Wenn Sie Kontoanmeldeinformationen, persönliche oder Zahlungsinformationen eingegeben oder eine Datei von dieser Domain heruntergeladen haben, ergreifen Sie sofort Maßnahmen. Nachfolgend finden Sie Ressourcen, die Ihnen helfen, den Vorfall zu melden und sich zu schützen.
Melden Sie sich bei Ihren örtlichen Behörden
Wählen Sie Ihr Land aus, um Offizielle Kontakte im Bereich Cyberkriminalität oder einen Beschwerdeentwurf erstellen → zu erhalten.
Jede beliebige Domain prüfen
Bedrohungsanalyse anhand gespeicherter Blocklisten, WHOIS, DNS und öffentlicher Scan-Beweise
Jetzt scannenPhishing melden
Melden Sie verdächtige Domains an unsere Bedrohungsdatenbank – schützen Sie die Community
MeldenEchtzeit-Bedrohungsfeed
Aktuelle Phishing-Meldungen und beobachtete Verfügbarkeitsänderungen
ÜberwachenBleiben Sie auf dem Laufenden, bleiben Sie sicher
Beobachten Sie aktuelle Bedrohungen oder legen Sie Widerspruch gegen diesen Eintrag ein, wenn Sie der Meinung sind, dass es sich um einen Fehlalarm handelt