t-mobile[.]knreb[.]cc
“knreb.cc | 522: Connection timed out”
t-mobile.knreb.cc — Contenido no disponible (HTTP 502). Suplantación de marca: T-mobile; Tipo de estafa: Brand Impersonation. Resumen de las pruebas: VirusTotal 13/93 (ADMINUSLabs, Criminal IP, Cluster25, CRDF, CyRadar); PhishDestroy score 89/100. Registrador: Gname.
El análisis detallado de PhishDestroy AI se mantiene en inglés para conservar el registro forense original.
Analysis of the domain t-mobile.knreb.cc indicates it is a brand impersonation scam targeting T-Mobile customers, classified as an elevated-risk threat. The domain was registered on February 21, 2026, through Gname.com Pte. Ltd. and is currently offline, returning a 522 connection timeout error with the page title 'knreb.cc | 522: Connection timed out.' Infrastructure analysis reveals the domain uses Cloudflare nameservers (paityn.ns.cloudflare.com and syeef.ns.cloudflare.com) and resolves to the IP address 172.67.204.48, hosted on Cloudflare's network (AS13335) in the United States. No SSL certificate is present, increasing the risk of unencrypted communications.
Security vendor detections are notable: 13 of 93 engines on VirusTotal flagged the domain as malicious, and it appears on at least one security blocklist, including PhishDestroy. The domain is linked to an 'Airdrop Scam' phishing kit, a tactic commonly used to deceive users into divulging personal or financial information under the guise of a promotional giveaway. Gridinsoft assigns a trust score of 0/100, further corroborating its malicious classification.
While the domain is currently offline, defenders should treat it as a confirmed threat due to its infrastructure, detection history, and association with a known phishing kit. Organizations are advised to block the domain at the DNS or proxy level, monitor for related subdomains or IPs, and alert users to the risks of interacting with unsolicited T-Mobile-themed promotions. The exact content of the site is not yet analyzed, but the available evidence strongly supports its classification as a brand impersonation scam.
Proceso de respuesta ante amenazas Pipeline
Estado de la lista de bloqueados pública
Análisis de VirusTotal
Datos y informes externos
PD-20260118-2DCD44 Recipient: complaint@gname.com ¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.